Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a separate security patch plugin for older versions.
JetBrains has reported attempted exploitation of CVE-2026-63077 against unpatched TeamCity On-Premises servers. The vulnerability is relevant when an attacker can reach the installation over HTTP or HTTPS.
An unauthenticated user can execute operating-system commands with the privileges of the TeamCity process. The issue is fixed in versions 2025.11.7 and 2026.1.3. JetBrains also provides a security patch plugin for older releases starting with 2017.1.
Suggested indicators include unknown agents whose names begin with scan and ConversionException errors. After protection is installed, ForbiddenClassException may indicate a blocked attempt, but a single log entry alone is not proof of compromise.
Internet-facing TeamCity installations should be updated immediately, and external access should be restricted to the minimum required. TeamCity Cloud is already protected, and cloud customers do not need to take additional action.