Back to News
Cybersecurity

Urgent Security Update Required for TeamCity Due to Critical Vulnerability

JetBrains has announced a critical vulnerability in TeamCity that poses severe risks to on-premise users, necessitating immediate updates.

JetBrains has issued an urgent advisory for users of on-premise versions of TeamCity following the identification of a critical vulnerability, CVE-2026-63077, with a CVSS score of 9.8. This flaw allows unauthorized attackers to execute arbitrary operating system commands without the need for authentication. The vulnerability affects all versions of TeamCity On-Premises and has been rectified in the latest updates, specifically versions 2025.11.7 and 2026.1.3. Notably, instances of TeamCity Cloud are not impacted by this issue, highlighting a significant difference between on-premise and cloud solutions in terms of security exposure.

For businesses utilizing TeamCity, the implications are significant. Organizations must prioritize updating to the latest versions to mitigate the risk of exploitation, as failure to do so could result in devastating breaches. This incident underscores the necessity for continuous monitoring and prompt patch management in maintaining cybersecurity hygiene. Moreover, the vulnerability exemplifies the evolving threat landscape where even established tools can harbor critical flaws, necessitating heightened vigilance in security practices, particularly as AI and automation become more integrated into development environments. Businesses should reassess their security protocols and ensure timely updates to safeguard against similar vulnerabilities in the future.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html)*