← Back to feed
vulnerabilities⚠ Single-originCVSS 9.8 criticalCVE-2026-630772 sources · 6d ago

CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

JetBrains is urging customers of on-premise versions of TeamCity to update following disclosure of a critical vulnerability allowing unauthenticated remote code execution.

Affected Amazon Web Services Cadence PyCharm TeamCity Antoni Tremblay CISA Daniel Gallo Jetbrains
2 outlets · 1 origin · Single-origin
India × 2

Through the Reader lens — JetBrains disclosed a critical unauthenticated remote code execution vulnerability in its on-premise TeamCity CI/CD server, tracked as CVE-2026-63077 with a CVSS score of 9.8. The flaw allows attackers to execute arbitrary code without authentication, posing severe risk to organizations running self-hosted TeamCity instances. JetBrains confirmed the vulnerability has already been exploited in the wild, revealing that attackers used it to breach the company's own Cadence cloud computing service and exfiltrate data. The vendor has released patched versions (2025.11.7 and 2026.1.3) and a security patch plugin for older versions dating back to 2017.1. Organizations running on-premise TeamCity deployments must prioritize immediate patching to prevent compromise. The breach of JetBrains' own infrastructure underscores the severity and active exploitation of this flaw, making delayed remediation particularly risky.

What to watch next

  • Patch TeamCity to 2025.11.7 or 2026.1.3 immediately
  • Apply security patch plugin for versions 2017.1+
  • Monitor for indicators of compromise in TeamCity logs
  • Audit Cadence service access if using JetBrains cloud

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

JetBrainsUrging immediate patching and disclosing breach impact

JetBrains disclosed a critical unauthenticated RCE vulnerability in on-premise TeamCity (CVE-2026-63077, CVSS 9.8) and urged customers to update to patched versions or apply the security patch plugin. The company also revealed that attackers exploited a TeamCity vulnerability to breach its Cadence cloud computing service, confirming real-world exploitation of the flaw.

The Hacker NewsThe Hacker News

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • JetBrains Cadence cloud service data breach · immediate
  • On-premise TeamCity customers patch required · immediate
  • On-premise TeamCity customers remote code execution risk · immediate
  • Jetbrains reputational damage · weeks

Sources (2)

CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol — Prism