Home / Jul 29, 2026 / Story
0
#4 The Hacker News general July 28, 2026 at 08:11 UTC

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

By [email protected] (The Hacker News)

AI Summary

JetBrains disclosed CVE-2026-63077 (CVSS 9.8), a critical unauthenticated remote code execution vulnerability affecting all on-premises versions of TeamCity CI/CD server, patched in versions 2025.11.7 and 2026.1.3. The flaw allows attackers to execute arbitrary OS commands without authentication, and TeamCity Cloud instances have already been remediated. Given TeamCity's history as a high-value supply chain attack target (notably in the 2023 SolarWinds-linked campaign), on-prem operators must update immediately.

Relevance score: 88.0/100

# More from July 29