JetBrains' own build server just became the easiest way into your company — zero login required

A 9.8-severity flaw in TeamCity On-Premises lets anyone with network access run commands on your build server — no credentials, no phishing, just a…

Aliteq
Priya Nair · Software & Systems Editor

Key point

CVE-2026-63077 is a CVSS 9.8 unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises.

Key point

The bug lives in TeamCity's agent polling protocol and lets an attacker bypass authentication entirely through deserialization of untrusted data.

Key point

Every on-premises version is affected. JetBrains patched it in 2025.11.7 and 2026.1.3, with a security patch plugin available for 2017.1 and later.

Key point

TeamCity Cloud customers are not affected and don't need to do anything.

Key point

Security researcher Antoni Tremblay privately reported the bug on July 10, 2026; JetBrains shipped a fix 17 days later, with no reported active exploitation yet.

Why deserialization bugs in CI/CD tools get security teams to drop everything

A build server doesn't just run code — it holds the source repo credentials, the signing keys, the deploy tokens and the artifact-registry logins for everything downstream of it. Popping one is…

Aliteq

Read the full story

JetBrains' own build server just became the easiest way into your company — zero login required

Read the full story on Aliteq