TeamCity 2026.1.3 and 2025.11.7 Security Updates Released

JetBrains releases TeamCity 2026.1.3 and 2025.11.7 with critical security patches. Upgrade now to fix CVE-2026-63077 and other vulnerabilities.

martes, 28 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Parches críticos de seguridad en TeamCity

JetBrains has released critical maintenance updates for TeamCity On-Premises, specifically versions 2026.1.3 and 2025.11.7, focusing on fixing more than twenty security vulnerabilities each. Among them, CVE-2026-63077 stands out as a critical flaw that allows attackers to bypass authentication mechanisms and execute arbitrary commands on the operating system with the privileges of the TeamCity server process. This type of vulnerability poses an extremely high risk for any organization using TeamCity as a continuous integration and delivery platform, as a compromise of the CI/CD server can expose the entire development workflow, including code repositories, credentials, and production artifacts.

The severity of this vulnerability cannot be underestimated. In enterprise environments where TeamCity manages build, test, and deployment pipelines, an attacker capable of executing commands could modify processes, steal stored secrets, alter artifacts, or even propagate to connected systems. Therefore, JetBrains strongly recommends updating to the patched versions as soon as possible. The 2026.1.3 update also fixes several functional issues affecting daily stability: incorrect or inconsistent test results when running test assemblies in parallel, failures in detecting changes in Perforce streams (causing commit hooks to match no VCS root instances), and errors when uploading artifacts to Amazon S3 due to the getBucketRegion method. These fixes remove friction that could delay deliveries or generate false positives in testing.

Staying up to date with minor versions of TeamCity is not only a security matter but also one of performance and compatibility. The updates include improvements in overall server performance, better integration with external tools (such as version control systems, cloud platforms, and artifact repositories), and faster, more stable builds. For companies that have adopted custom software development, a robust CI/CD platform is essential to ensure that every code change is reliably tested and deployed. Version 2026.1.3 shares the same data format as all 2026.1.x releases, allowing upgrades or even downgrades without needing full backups or restorations, thus facilitating software lifecycle management.

From a technical and business perspective, security in continuous integration tools has become a pillar of DevSecOps. Organizations integrating cloud services such as AWS or Azure into their pipelines must ensure that the central orchestrator (TeamCity) is protected against advanced threats. The CVE-2026-63077 vulnerability is a reminder that no component of the development ecosystem is risk-free. Therefore, companies like Q2BSTUDIO, specialized in custom software development, artificial intelligence, and cybersecurity, recommend establishing a plan for regular updates and security audits. At Q2BSTUDIO, we help our clients design and implement secure CI/CD solutions, whether through building custom applications that integrate AI agents to automate testing, or by adopting business intelligence dashboards with Power BI that monitor pipeline status in real time.

The emergence of AI agents in development workflows is changing how builds and anomaly detections are managed. An AI agent could analyze TeamCity logs to identify failure patterns before they affect production, or even propose automatic fixes. However, for these innovations to be secure, the underlying infrastructure must be up to date. Version 2025.11.7 also includes patches for similar vulnerabilities, so even those using older versions of the 2025.x branch should update without delay. The update can be performed via the automatic feature included in TeamCity, by downloading the installer from the JetBrains website, or using the updated Docker image.

In a context where cybersecurity is a strategic priority, ignoring these updates can expose the organization to data breaches, financial losses, and reputational damage. That is why at Q2BSTUDIO we offer security consulting services, including pentesting and vulnerability analysis, as well as cloud integration solutions on AWS or Azure for development and production environments. Moreover, our Business Intelligence expertise allows us to help companies create control dashboards with Power BI that visualize security and performance metrics of pipelines, facilitating informed decision-making. The combination of an updated TeamCity, robust security policies, and intelligent use of artificial intelligence can transform how organizations deliver software, reducing risks and accelerating innovation.

In summary, the release of TeamCity 2026.1.3 and 2025.11.7 underscores the importance of keeping development tools up to date. Whether your team relies on integrations with Perforce, Amazon S3, or any other system, updating now is the best decision to protect your workflows. At Q2BSTUDIO, we are committed to helping companies adopt best practices in software development, from creating custom applications to implementing AI agents and cybersecurity solutions. If you need assistance planning your upgrade or reviewing the security of your CI/CD infrastructure, do not hesitate to contact us. The security and efficiency of your pipelines start with a timely update.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.