Critical Security Issue in TeamCity On-Premises (CVE-2026-63077) – Update Now

A critical vulnerability in TeamCity On-Premises allows unauthenticated RCE. Update to version 2025.11.7 or 2026.1.3 to secure your server.

martes, 28 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Actualice a la versión parcheada para evitar RCE

On July 10, 2026, a critical vulnerability in TeamCity On-Premises was reported privately, identified as CVE-2026-63077, which has put all development and operations teams using this continuous integration tool on high alert. The flaw allows an unauthenticated attacker with only HTTP or HTTPS access to the server to bypass security controls and execute arbitrary commands on the underlying operating system. This means any TeamCity server exposed to the internet or even to non-segmented internal networks can be fully compromised, exposing sensitive data, stored credentials, and the integrity of CI/CD pipelines.

The vulnerability affects all versions of TeamCity On-Premises up to the patch date, making it a high-impact threat. Security researchers have confirmed it can be exploited through the agent polling protocol without any user interaction or prior privileges. Once exploited, the attacker gains the same permissions as the TeamCity server process, which in many environments equates to full system control. Although no active attacks have been detected as of this advisory, the severity of the CVE demands immediate action from any organization maintaining on-premises instances.

JetBrains, the company behind TeamCity, has released patched versions 2025.11.7 and 2026.1.3 that fully fix the flaw. Additionally, for teams unable to upgrade immediately due to compatibility constraints or change processes, a security patch plugin compatible with TeamCity 2017.1 and later has been published. This plugin can be downloaded and installed manually, or through the administration panel in recent versions. It is important to note that the plugin only addresses this specific vulnerability, so the primary recommendation remains to migrate to the latest stable version to benefit from all accumulated improvements.

Beyond applying the patch, TeamCity server security must be approached from a comprehensive perspective. As a best practice, network access should be limited to trusted systems, preferably through VPN connections, and the server should run with minimal necessary privileges. It is also advisable to host the server on a dedicated machine separate from build agents and avoid exposing the login screen or REST API to the internet without additional protection layers. These measures significantly reduce the attack surface and hinder exploitation of any future vulnerabilities.

CVE-2026-63077 highlights the importance of a robust cybersecurity strategy in development and deployment environments. At Q2BSTUDIO, we understand that security is not an afterthought but a fundamental pillar of any software project. That is why we offer security auditing, penetration testing, and cybersecurity consulting services to help companies identify and mitigate risks before they are exploited. Our team works with modern tools and agile methodologies to ensure your CI/CD systems, such as TeamCity, are protected against critical threats.

In addition to cybersecurity, at Q2BSTUDIO we accompany organizations in their digital transformation through the development of custom software applications that integrate seamlessly with cloud infrastructures. Whether migrating your TeamCity servers to AWS or Azure, or designing cloud-native solutions from scratch, we help reduce costs, improve scalability, and increase operational resilience. The cloud offers advantages such as automatic patching and high availability, which can minimize the impact of vulnerabilities like this one.

Furthermore, artificial intelligence (AI) and intelligent agents are revolutionizing how we monitor and protect systems. At Q2BSTUDIO, we combine AI with data analytics (Business Intelligence via Power BI) to detect anomalous patterns in real time, anticipate attacks, and automate responses. Our AI agents can monitor TeamCity logs, identify suspicious behaviors, and trigger alerts or even corrective actions without human intervention. This extra proactive defense layer is especially valuable in environments where reaction time is critical.

For companies that have not yet migrated to TeamCity Cloud, the on-premises option remains valid but requires constant security management. Immediate upgrade to versions 2025.11.7 or 2026.1.3 is the first unavoidable step. If your team needs help with the upgrade process, patch plugin installation, or security architecture review, Q2BSTUDIO offers specialized technical support. Our engineers know TeamCity’s intricacies in depth and can advise you on keeping your environment productive and secure.

Do not wait for an attacker to exploit this vulnerability. Cybersecurity is not a luxury; it is a necessity in today’s landscape. Contact us for a free consultation and discover how we can strengthen your development infrastructure with custom software, cloud, BI, and AI agent solutions. Your CI/CD pipeline deserves the best protection.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.