In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
https://www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/
https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
https://securityaffairs.com/196169/security/jetbrains-patches-cvss-9-8-teamcity-flaw-allowing-server-takeover.html
https://www.jetbrains.com/privacy-security/issues-fixed/
Source: Mitre, NVD
Published: 2026-07-27
Updated: 2026-07-28
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00649