Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Anthropic CEO: Don’t ban cheap AI — but clamp down on China

    July 28, 2026

    Fit schools, hospitals and new homes with air conditioning, say Lib Dems

    July 28, 2026

    Home Office used ‘AI hallucinated’ information to refuse asylum claim, judge suggests | Immigration and asylum

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anthropic CEO: Don’t ban cheap AI — but clamp down on China
    • Fit schools, hospitals and new homes with air conditioning, say Lib Dems
    • Home Office used ‘AI hallucinated’ information to refuse asylum claim, judge suggests | Immigration and asylum
    • Trump’s waning sway over the world
    • Thea Energy lands $20M federal grant to build its magnets for fusion reactors
    • Why your AI safety certificates are worthless at runtime
    • How a crypto exchange secretly hid $53M in stolen crypto to prevent a bank run
    • New images reveal Betelgeuse’s buddy star
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 28, 2026Vulnerability / Enterprise Security

    JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

    The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026.

    “If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said.

    The flaw allows unauthenticated remote code execution via the agent polling protocol to sidestep authentication checks and achieve command execution. Depending on the privileges granted to the TeamCity server process, a successful compromise can lead to the exposure of TeamCity data, configurations, and stored credentials, or modification of server state.

    Cybersecurity

    Besides releasing versions 2025.11.7 and 2026.1.3, JetBrains has released a security patch plugin for versions 2017.1+ so that customers who are unable to apply an update can still patch their environments. There is no evidence to indicate that the flaw has been exploited in the wild.

    “The security patch plugin will address only the vulnerability described above (CVE-2026-63077),” JetBrains cautioned. “We always recommend upgrading your server to the latest version to benefit from many other security updates.”

    As best practices, customers are advised to consider requiring VPN connections or implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers.

    “Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities,” it added.

    Attackers Commands critical Flaw Logging Run TeamCity
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Why your AI safety certificates are worthless at runtime

    How a crypto exchange secretly hid $53M in stolen crypto to prevent a bank run

    Hush Security Raises $30 Million for AI Agent Governance

    Google Adopts New Threat Actor Naming System

    Coca-Cola confirms data theft in Fairlife ransomware attack

    New Certighost PoC exploit lets attackers hijack Windows domains

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Anthropic CEO: Don’t ban cheap AI — but clamp down on China

    July 28, 2026

    Fit schools, hospitals and new homes with air conditioning, say Lib Dems

    July 28, 2026

    Home Office used ‘AI hallucinated’ information to refuse asylum claim, judge suggests | Immigration and asylum

    July 28, 2026

    Trump’s waning sway over the world

    July 28, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Anthropic CEO: Don’t ban cheap AI — but clamp down on China

    July 28, 2026

    Fit schools, hospitals and new homes with air conditioning, say Lib Dems

    July 28, 2026

    Home Office used ‘AI hallucinated’ information to refuse asylum claim, judge suggests | Immigration and asylum

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.