All TeamCity On-Premises versions are affected by CVE-2026-63077. JetBrains says an unauthenticated attacker with HTTP(S) access to a vulnerable server may bypass authentication and execute operating-system commands as the TeamCity server process. JetBrains reports active and attempted exploitation of unpatched servers. Upgrade to TeamCity 2025.11.7 or 2026.1.3; if you cannot upgrade immediately, install the vendor’s security patch plugin and restrict external access while arranging remediation. TeamCity Cloud customers need no action, according to JetBrains.
Is my TeamCity server affected?
JetBrains’ advisory covers all TeamCity On-Premises versions. The described attack requires HTTP(S) access to a vulnerable server; a server reachable by an attacker over the network is therefore at risk. JetBrains says TeamCity Cloud has already received the necessary mitigations, so Cloud customers do not need to take action for this vulnerability. See the JetBrains CVE-2026-63077 advisory for the vendor’s scope and guidance.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages | $22.99 | Buy on Amazon |
JetBrains’ August follow-up reports that it received reports of active and attempted exploitation targeting unpatched servers after its initial July 27, 2026 announcement. That is a vendor report; it does not establish a count of affected servers or confirmed compromises. Treat an unpatched, reachable On-Premises instance as requiring prompt remediation. See JetBrains’ exploitation update.
What can an attacker do?
According to JetBrains, CVE-2026-63077 lets an unauthenticated attacker with HTTP(S) access bypass authentication by using the TeamCity agent polling protocol. If successful, the attacker can execute operating-system commands with the privileges of the TeamCity server process.
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
The practical impact depends on that process’s permissions and what the server can access. JetBrains warns that an attack could expose data, configurations, and stored credentials; alter server state; and potentially compromise build artifacts and downstream CI/CD pipelines. The vulnerability was privately reported to JetBrains by Antoni Tremblay on July 10, 2026.
How do I patch CVE-2026-63077?
Upgrade to a fixed release
JetBrains identifies TeamCity 2025.11.7 and 2026.1.3 as fixed. Upgrading is the broader maintenance option: JetBrains says each release addresses more than 20 security vulnerabilities, so these versions include security fixes beyond CVE-2026-63077. Consult the TeamCity 2026.1.3 and 2025.11.7 release announcement and follow your normal upgrade procedure for the applicable release.
Install the security patch plugin if you cannot upgrade yet
If an immediate upgrade is not possible, JetBrains offers a security patch plugin for TeamCity 2017.1 and later. It addresses CVE-2026-63077 alone; it is not equivalent to upgrading for the other security fixes in the fixed releases. JetBrains recommends upgrading when possible.
For TeamCity 2024.03 and newer, JetBrains says security patch plugins are automatically downloaded. Administrators can review pending patches at Administration | Updates, under Available security updates, when notifications are configured. Refer to the advisory for the vendor’s patch instructions.
What if I cannot patch immediately?
A network restriction is an interim risk-reduction measure, not the software fix. JetBrains recommends that administrators with a publicly accessible server that cannot be patched right away temporarily restrict external access, then apply the release or plugin fix as soon as possible. Its follow-up guidance also recommends limiting network access to trusted networks.
- Run TeamCity with only the operating-system privileges it needs.
- Host the TeamCity server separately from build agents.
- For an internet-facing server, consider VPN access or an additional security layer as a longer-term control.
These measures reduce exposure or potential impact; they do not replace installing the fix.
Quick Recap
Choose the remediation that matches your deployment
| Situation | Action | Scope |
|---|---|---|
| TeamCity On-Premises, upgrade possible | Upgrade to 2025.11.7 or 2026.1.3. | Fixes CVE-2026-63077 and includes other security updates; JetBrains says each release addresses more than 20 vulnerabilities. |
| TeamCity On-Premises, upgrade not immediately possible | Install the security patch plugin, available for TeamCity 2017.1 and later; temporarily restrict external access if the server is publicly accessible. | The plugin addresses CVE-2026-63077 alone. Access restrictions are interim exposure reduction, not a software fix. |
| TeamCity Cloud | No action required for this CVE, according to JetBrains. | JetBrains says the necessary mitigations have already been applied. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

