29 July 2026
Reference: CVE-2026-63077
1. What is being reported?
The vulnerability allows unauthorised users to execute commands remotely on systems running certain versions of JetBrains TeamCity. This happens through the way TeamCity communicates with its agents, potentially letting attackers take control without any login credentials.
2. What this means in plain English
If your organisation uses TeamCity for software development or automation, attackers might exploit this flaw to access your systems, steal data, or cause damage. This risk is critical because it requires no login, making it easier for attackers to succeed.
3. Could this affect a small business?
Small businesses or charities using JetBrains TeamCity versions before 2026.1.3 or 2025.11.7 could be affected. If you do not use this software, or if your IT provider has already updated it, you are likely not at risk.
4. What to do now
- Check if your organisation uses JetBrains TeamCity and identify the version installed.
- Contact your IT provider or software supplier to confirm if your TeamCity version is vulnerable.
- If vulnerable, arrange to update TeamCity to version 2026.1.3 or later, or 2025.11.7 or later, as recommended by JetBrains.
- Monitor your systems for unusual activity and ensure regular backups are in place.
5. Ask your IT provider
Can you confirm whether our JetBrains TeamCity software is updated to a safe version that fixes the recent critical remote code execution vulnerability?
6. Bottom line
If you use JetBrains TeamCity, make sure it is updated promptly to prevent attackers from taking control without logging in.
Information based on CISA KEV, NVD, and reputable security news reporting.