ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

TeamCity Urgently Patched for Unauthenticated Code Execution Flaw (CVE-2026-63077)

Source headline: Critical Code Execution Vulnerability Patched in TeamCity

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

JetBrains TeamCity has been patched for a critical code execution vulnerability tracked as CVE-2026-63077. The issue can be exploited without authentication through the agent polling protocol. Successful exploitation could allow an attacker to run code in the context of the affected TeamCity instance. The flaw was addressed by vendor fixes intended to stop malicious requests targeting the polling endpoint. Administrators should update TeamCity to the patched versions and verify the agent polling behavior is no longer exposed to untrusted networks.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#unauthenticated #code-execution #patch #agent-polling #cve-2026-63077 #teamcity
Original reporting SecurityWeek Critical Code Execution Vulnerability Patched in TeamCity
Open original source