
CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE
A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed CVE-2026-63077, a vulnerability that could allow unauthenticated attackers to execute arbitrary operating system commands.
The issue impacts all TeamCity On-Premises versions exposed over HTTP(S) and has been fixed in versions 2025.11.7 and 2026.1.3. Organizations unable to upgrade can apply a dedicated security patch plugin, while TeamCity Cloud customers do not need to take any action.
CVE-2026-63077 Enables Unauthenticated Access Over HTTP(S)
According to the advisory, CVE-2026-63077 allows an attacker with HTTP(S) access to a vulner...