QCKL News

JetBrains warns of attacks on unpatched TeamCity On-Premises servers

CVE-2026-63077 allows an unauthenticated attacker to execute operating-system commands when an unpatched TeamCity On-Premises server is reachable over HTTP(S).

Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a separate security patch plugin for older versions.

JetBrains warns of attacks on unpatched TeamCity On-Premises servers

JetBrains has reported attempted exploitation of CVE-2026-63077 against unpatched TeamCity On-Premises servers. The vulnerability is relevant when an attacker can reach the installation over HTTP or HTTPS.

An unauthenticated user can execute operating-system commands with the privileges of the TeamCity process. The issue is fixed in versions 2025.11.7 and 2026.1.3. JetBrains also provides a security patch plugin for older releases starting with 2017.1.

Suggested indicators include unknown agents whose names begin with scan and ConversionException errors. After protection is installed, ForbiddenClassException may indicate a blocked attempt, but a single log entry alone is not proof of compromise.

Internet-facing TeamCity installations should be updated immediately, and external access should be restricted to the minimum required. TeamCity Cloud is already protected, and cloud customers do not need to take additional action.

Primary sources