Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
    • Bitcoin ETFs Post First Monthly Inflow Since April
    • Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr
    • Yemen’s Houthis deny plan to charge ships transiting Red Sea | Houthis News
    • The tangled financial web at the heart of Reform UK | Reform UK
    • Turn failing water firms into not-for-profit cooperatives, MPs and mayors tell PM | Water industry
    • Europe’s long hot summer
    • Not just OpenAI – Anthropic says Claude’s hacking spree ‘falls short of ideal behavior’
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Code Execution Vulnerability Patched in TeamCity 

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 1, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication.

    Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE).

    “An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains explains in its advisory.

    Depending on the available privileges, an attacker could access TeamCity data, configurations, and credentials, could tamper with the server state, and could potentially compromise build artifacts and downstream CI/CD pipelines.

    According to JetBrains, the flaw affects all TeamCity On-Premises versions. The company has already rolled out mitigations for TeamCity Cloud instances and has no evidence that the bug has been exploited in the wild.

    “A fix for this vulnerability has been introduced in versions 2025.11.7 and 2026.1.3. We have also released a security patch plugin for 2017.1+ so that customers who are unable to upgrade can still patch their environments,” JetBrains announced.

    Advertisement. Scroll to continue reading.

    Users are advised to download and install either the latest version of TeamCity or the security patch plugin as soon as possible (the plugin resolves only this CVE, the company notes).

    JetBrains also recommends limiting access to internet-facing TeamCity servers, running all servers with the minimum required operating system privileges, and using VPN connections or implementing additional protections to prevent unauthorized access.

    “TeamCity servers should also run on dedicated hosts separate from build agents,” the company notes.

    Related: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

    Related: Chrome 151 Patches 370 Vulnerabilities

    Related: Cisco Secure FMC Zero-Day Exploited in the Wild

    Related: Critical VM Escape Vulnerability Patched in VMware ESXi

    Code critical Execution Patched TeamCity Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

    Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

    Online ad firm Adform’s script compromised to steal cryptocurrency

    HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

    Arch Linux disables AUR package adoption to stop malware flood

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Yemen’s Houthis deny plan to charge ships transiting Red Sea | Houthis News

    August 1, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.