Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Minnesota teen balances graduation, new roles after dad’s deportation to Laos

    July 28, 2026

    Led By Donkeys wins compensation over seizure of Gaza protest banner | Led By Donkeys

    July 28, 2026

    Gironde wildfires pick up as French region braces for new 40C heatwave

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Minnesota teen balances graduation, new roles after dad’s deportation to Laos
    • Led By Donkeys wins compensation over seizure of Gaza protest banner | Led By Donkeys
    • Gironde wildfires pick up as French region braces for new 40C heatwave
    • Latest Updates: Lindsey Graham Gets a Washington Goodbye
    • Conservative MP accuses French navy of firing shots near him in Channel | Immigration and asylum
    • You’ve been using your power bank wrong, and airline rules make that obvious
    • Over 24,000 exposed server BMCs leak password hash via decades-old flaw
    • Morning Minute: Strategy Chooses Cash, STRC Over BTC
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 28, 2026Vulnerability / Enterprise Security

    JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

    The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026.

    “If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said.

    The flaw allows unauthenticated remote code execution via the agent polling protocol to sidestep authentication checks and achieve command execution. Depending on the privileges granted to the TeamCity server process, a successful compromise can lead to the exposure of TeamCity data, configurations, and stored credentials, or modification of server state.

    Cybersecurity

    Besides releasing versions 2025.11.7 and 2026.1.3, JetBrains has released a security patch plugin for versions 2017.1+ so that customers who are unable to apply an update can still patch their environments. There is no evidence to indicate that the flaw has been exploited in the wild.

    “The security patch plugin will address only the vulnerability described above (CVE-2026-63077),” JetBrains cautioned. “We always recommend upgrading your server to the latest version to benefit from many other security updates.”

    As best practices, customers are advised to consider requiring VPN connections or implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers.

    “Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities,” it added.

    Attackers Commands critical Flaw Logging Run TeamCity
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Over 24,000 exposed server BMCs leak password hash via decades-old flaw

    Why your AI safety certificates are worthless at runtime

    How a crypto exchange secretly hid $53M in stolen crypto to prevent a bank run

    Hush Security Raises $30 Million for AI Agent Governance

    Google Adopts New Threat Actor Naming System

    Coca-Cola confirms data theft in Fairlife ransomware attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Minnesota teen balances graduation, new roles after dad’s deportation to Laos

    July 28, 2026

    Led By Donkeys wins compensation over seizure of Gaza protest banner | Led By Donkeys

    July 28, 2026

    Gironde wildfires pick up as French region braces for new 40C heatwave

    July 28, 2026

    Latest Updates: Lindsey Graham Gets a Washington Goodbye

    July 28, 2026
    Latest Posts

    DNV awards world’s first certification for wave energy technology

    July 21, 2026

    Tropical Storm Bertha threatens US Gulf coast

    July 21, 2026

    Road deaths fall by 21% globally but stronger action is needed to save lives

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Minnesota teen balances graduation, new roles after dad’s deportation to Laos

    July 28, 2026

    Led By Donkeys wins compensation over seizure of Gaza protest banner | Led By Donkeys

    July 28, 2026

    Gironde wildfires pick up as French region braces for new 40C heatwave

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.