CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
JetBrains is urging customers of on-premise versions of TeamCity to update following disclosure of a critical vulnerability allowing unauthenticated remote code execution.

Through the Reader lens — JetBrains disclosed a critical unauthenticated remote code execution vulnerability in its on-premise TeamCity CI/CD server, tracked as CVE-2026-63077 with a CVSS score of 9.8. The flaw allows attackers to execute arbitrary code without authentication, posing severe risk to organizations running self-hosted TeamCity instances. JetBrains confirmed the vulnerability has already been exploited in the wild, revealing that attackers used it to breach the company's own Cadence cloud computing service and exfiltrate data. The vendor has released patched versions (2025.11.7 and 2026.1.3) and a security patch plugin for older versions dating back to 2017.1. Organizations running on-premise TeamCity deployments must prioritize immediate patching to prevent compromise. The breach of JetBrains' own infrastructure underscores the severity and active exploitation of this flaw, making delayed remediation particularly risky.
What to watch next
- Patch TeamCity to 2025.11.7 or 2026.1.3 immediately
- Apply security patch plugin for versions 2017.1+
- Monitor for indicators of compromise in TeamCity logs
- Audit Cadence service access if using JetBrains cloud
