Vulnerability
Published 2026-08-24
Verified 2026-09-19
TeamCity On-Premises unauthenticated RCE (CVE-2026-63077), exploited in Australia
Unauthenticated remote code execution in JetBrains TeamCity On-Premises via the agent polling protocol. ASD's ACSC observed active exploitation against On-Premises servers in Australia. All On-Premises versions are affected. TeamCity Cloud is not. Patch to 2025.11.7 or 2026.1.3, or apply the vendor security patch plugin if you cannot upgrade.
- Product
- JetBrains TeamCity On-Premises
- Versions
- All On-Premises versions before the fixed releases
- CVSS
- (CVSS 3.1, JetBrains CNA via NVD)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- yes
- Patch to
- 2025.11.7 or 2026.1.3
Primary: ASD's ACSC advisory · Vendor: JetBrains advisory · CVE: CVE-2026-63077 · Australian Cyber Security Magazine (secondary)
