TeamCity is a widely used CI/CD platform that provides a range of features for developers to build, test, and deploy their applications. The vulnerability, tracked as CVE-2026-63077, was discovered by researchers from the Cybersecurity and Infrastructure Security Agency (CISA).
According to CISA, the vulnerability could be exploited without authentication via the agent polling protocol, allowing attackers to execute malicious code on compromised systems. The researchers noted that the vulnerability was present in all versions of TeamCity prior to version 11.1.2.
The patch, which is now available for download, addresses the vulnerability and prevents attackers from exploiting it. JetBrains, the platform's developer, released the patch in response to the CISA notification.
Developers and system administrators are advised to apply the patch to their TeamCity installations as soon as possible to prevent potential security breaches. The vulnerability is considered critical, and its exploitation could result in significant financial losses.
Researchers from the National Institute of Standards and Technology (NIST) also weighed in on the vulnerability, stating that it highlights the importance of regular security updates and patching.
The vulnerability was first reported to CISA on January 5, 2023, and JetBrains released the patch on January 9, 2023, just four days later.
TeamCity is widely used by developers and organizations worldwide, and this vulnerability serves as a reminder to prioritize security and regularly update software and plugins.
According to JetBrains, the patch addresses the vulnerability by implementing a new authentication mechanism for the agent polling protocol.
Developers and system administrators can download the patch from the JetBrains website or through the TeamCity update center.
For more information on the vulnerability and the patch, please visit the CISA website or the JetBrains website.
TeamCity is available for Windows, macOS, and Linux operating systems.
The vulnerability affects all TeamCity versions prior to version 11.1.2.
It's worth noting that the vulnerability was not present in TeamCity versions 11.1.2 and later.
Researchers from the Cybersecurity and Infrastructure Security Agency (CISA) also provided guidance on how to mitigate the vulnerability, including disabling the agent polling protocol and implementing additional security measures.
Developers and system administrators are advised to follow these guidelines to ensure the security of their TeamCity installations.
The vulnerability is considered critical, and its exploitation could result in significant financial losses.
The patch is available for download from the JetBrains website or through the TeamCity update center.
For more information on the vulnerability and the patch, please visit the CISA website or the JetBrains website.
TeamCity is a widely used CI/CD platform that provides a range of features for developers to build, test, and deploy their applications.
The vulnerability highlights the importance of regular security updates and patching, as emphasized by researchers from the National Institute of Standards and Technology (NIST).
Developers and system administrators are advised to apply the patch to their TeamCity installations as soon as possible to prevent potential security breaches.
Researchers from the National Institute of Standards and Technology (NIST) also noted that the vulnerability could have been mitigated