ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
TeamCity Urgently Patched for Unauthenticated Code Execution Flaw (CVE-2026-63077)
Source headline: Critical Code Execution Vulnerability Patched in TeamCity
Threat level
Critical
Signal strength
85/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
JetBrains TeamCity has been patched for a critical code execution vulnerability tracked as CVE-2026-63077. The issue can be exploited without authentication through the agent polling protocol. Successful exploitation could allow an attacker to run code in the context of the affected TeamCity instance. The flaw was addressed by vendor fixes intended to stop malicious requests targeting the polling endpoint. Administrators should update TeamCity to the patched versions and verify the agent polling behavior is no longer exposed to untrusted networks.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
SecurityWeek
Critical Code Execution Vulnerability Patched in TeamCity
Open original source