🔴 Critical | Source: The Hacker News
A critical vulnerability (CVE-2026-63077, CVSS 9.8) in JetBrains TeamCity On-Premises allows unauthenticated attackers to execute arbitrary operating system commands. All on-premises versions are affected, with fixes available in versions 2025.11.7 and 2026.1.3. TeamCity is widely used in CI/CD pipelines, making this a significant supply chain risk for organisations that have not yet patched.
Security Architect’s Take: Patch all TeamCity On-Premises instances to version 2025.11.7 or 2026.1.3 immediately — unauthenticated RCE on a CI/CD platform represents a critical supply chain exposure. If patching is not immediately possible, restrict network access to TeamCity servers to trusted IP ranges and audit recent build logs for signs of unauthorised command execution.
Original advisory: Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In