← Back to Tech & Science

JetBrains Issues Critical Alert for TeamCity Vulnerability Allowing Remote Code Execution

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

MOSCOW — JetBrains has issued an urgent security advisory regarding a critical flaw in its on-premises continuous integration server, TeamCity, which allows unauthenticated attackers to execute arbitrary operating system commands. The vulnerability, identified as CVE-2026-63077, was disclosed on July 28, 2026, prompting immediate action from the software developer and security researchers worldwide.

The defect resides within the agent polling protocol used by TeamCity servers to communicate with build agents. Security analysis indicates that an attacker can exploit this flaw to bypass standard authentication checks entirely. By sending a specially crafted request through the vulnerable endpoint, malicious actors could gain unauthorized access to the server's underlying operating system and run commands without requiring valid credentials or prior session establishment.

Antoni Tremblay, who discovered the vulnerability, reported the issue directly to JetBrains' security team. The company confirmed that the flaw poses an immediate risk of remote code execution (RCE), a classification typically reserved for vulnerabilities allowing attackers to take full control of affected systems. Because TeamCity is widely deployed in enterprise environments to manage software development pipelines, successful exploitation could lead to data theft, infrastructure compromise, or the injection of malicious code into production builds.

JetBrains stated that the vulnerability affects specific on-premises versions of TeamCity and does not impact its cloud-hosted services. The company has released patches for all affected versions and is urging administrators to update their systems immediately. Until updates are applied, JetBrains recommends isolating vulnerable servers from public networks or implementing strict firewall rules to block unauthorized access to the agent polling ports.

The discovery highlights ongoing challenges in securing complex build automation tools that often require open network interfaces to function correctly. While TeamCity's architecture relies on agents periodically checking for tasks, this mechanism was found to be insufficiently protected against unauthenticated requests targeting specific protocol handlers.

Security experts note that the timeline between disclosure and patch availability is critical in mitigating such risks. As of late July 2026, no widespread exploitation of CVE-2026-63077 has been publicly confirmed, though researchers warn that zero-day attacks could be occurring silently within targeted organizations.

Questions remain regarding the extent of exposure among enterprises running older or unsupported versions of TeamCity. Additionally, it is unclear whether similar vulnerabilities exist in other components of the JetBrains ecosystem or if this represents an isolated incident specific to the agent polling implementation. Administrators are advised to review their patch management schedules and verify that all instances have been updated to the latest secure version.

Discussion

0 / 2000