JetBrains has issued a product security update advisory.
The advisory applies to TeamCity On-Premises; all versions are affected except for versions 2025.11.7 And 2026.1.3.
The resolved vulnerability is CVE-2026-63077, an unauthenticated remote code execution vulnerability in the agent polling protocol of TeamCity On-Premises.
This vulnerability allows remote code execution without authentication, posing a risk that a threat actor could compromise the system.
JetBrains has provided a patch through the latest update and recommends updating to version 2025.11.7 Or 2026.1.3 Or later, following the instructions on the reference site.
The reference site is “Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 Or 2026.1.3 Now.”