All stories
criticalExploited VulnerabilitiesCVE-2026-63077

Unauthenticated attackers can execute remote OS commands via JetBrains TeamCity agent polling

馃毃 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials. Update to versions 2026.1.3 or 2025.11.7 immediately to secure your CI/CD pipeline.

Summary

A critical vulnerability in JetBrains TeamCity allows unauthenticated attackers to execute remote code on affected systems. The flaw resides within the agent polling protocol, providing a direct path for unauthorized command execution. This vulnerability carries a CVSS score of 9.8, reflecting its high impact and ease of exploitation.

The issue affects versions of TeamCity prior to the release of 2026.1.3 and 2025.11.7. Because the exploit can be triggered without any user interaction or authentication, it poses a significant risk to organizations relying on TeamCity for continuous integration and deployment workflows.

Technical details

The vulnerability, identified as CVE-2026-63077, centers on how the TeamCity server handles requests through its agent polling protocol. This protocol is a core component of the communication between the central TeamCity server and its distributed build agents.

An attacker can exploit this mechanism to achieve remote code execution (RCE). By sending crafted requests via the polling protocol, an unauthenticated actor can bypass standard security controls to run arbitrary commands on the underlying infrastructure. The high CV-SS score of 9.8 underscores that the attack vector is network-based and requires no specialized privileges or user intervention.

Affected products and fixed versions

The vulnerability impacts all TeamCity installations that have not yet applied the latest security patches. Organizations running older versions are susceptible to unauthenticated RCE via the agent polling protocol.

To mitigate this risk, users must upgrade to one of the following patched versions:

Product Fixed Version Status
JetBrains TeamCity 2026.1.3 Patched
JetBrains TeamCity 2025.11.7 Patched

Defender guidance

Immediate patching is the primary defense against this vulnerability. Because the flaw allows unauthenticated access, there is no way to verify if an attacker has already attempted to interact with your agent polling endpoint without checking system logs and updating the software.

Prioritize upgrading TeamCity instances that are exposed to the internet or reside in less-trusted network segments. If an immediate upgrade is not possible due to deployment constraints, ensure that access to the TeamCity server and its communication ports is strictly limited via firewall rules to known, trusted agent IP addresses. This can reduce the attack surface by preventing unauthorized external entities from reaching the polling protocol.

Monitor your CI/CD environment for unusual process executions or unexpected network connections originating from the TeamCity server or its build agents. While specific indicators of compromise are not provided in the current advisory, any deviation from standard build behaviors should be investigated.

Sources

  1. https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
  2. https://www.jetbrains.com/privacy-security/issues-fixed/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -