#4
SecurityWeek
general
July 31, 2026 at 06:50 UTC
Critical Code Execution Vulnerability Patched in TeamCity
By Ionut Arghire
AI Summary
JetBrains patched a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-63077 in TeamCity, exploitable via the agent polling protocol without requiring any credentials. TeamCity is widely used in enterprise CI/CD pipelines, making unauthenticated RCE a high-severity risk for software supply chain integrity. Organizations running on-premises TeamCity instances should apply the patch immediately and audit agent communication channels.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →