
Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
A critical unauthenticated remote code execution (RCE) vulnerability has been discovered in TeamCity On-Premises, JetBrains’ widely used continuous integration and continuous delivery (CI/CD) server. Tracked as CVE-2026-63077, the flaw allows attackers with mere HTTP(S) access to a vulnerable server to bypass authentication entirely and execute arbitrary operating system commands with the privileges of the TeamCity […]
The post Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands appeared first on Cyber Security News.