Close Menu
    What's Hot

    Hungary’s thawing relations with EU provide lucrative trade for foreign funds

    Can the New York Times Save Journalism From Our AI Overlords?

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    Facebook X (Twitter) Instagram
    Trending
    • Hungary’s thawing relations with EU provide lucrative trade for foreign funds
    • Can the New York Times Save Journalism From Our AI Overlords?
    • Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
    • There’s a Way to Prevent Ovarian Cancer. Few Know About It.
    • Senate Democrats Press Blanche on Times Subpoenas
    • Graham to Be Honored at Funeral Services This Week. Here’s How to Watch.
    • ‘We Are Not Learning Anything’: India’s Gen Z Rage Is a Test for Modi
    • France and Spain Race to Tamp Down Wildfires Before Heat Wave Hits
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    adminBy adminJuly 28, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 28, 2026Vulnerability / Enterprise Security

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

    The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026.

    “If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said.

    The flaw allows unauthenticated remote code execution via the agent polling protocol to sidestep authentication checks and achieve command execution. Depending on the privileges granted to the TeamCity server process, a successful compromise can lead to the exposure of TeamCity data, configurations, and stored credentials, or modification of server state.

    Cybersecurity

    Besides releasing versions 2025.11.7 and 2026.1.3, JetBrains has released a security patch plugin for versions 2017.1+ so that customers who are unable to apply an update can still patch their environments. There is no evidence to indicate that the flaw has been exploited in the wild.

    “The security patch plugin will address only the vulnerability described above (CVE-2026-63077),” JetBrains cautioned. “We always recommend upgrading your server to the latest version to benefit from many other security updates.”

    As best practices, customers are advised to consider requiring VPN connections or implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers.

    “Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities,” it added.

    Attackers Commands critical flaw logging run TeamCity
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThere’s a Way to Prevent Ovarian Cancer. Few Know About It.
    Next Article Can the New York Times Save Journalism From Our AI Overlords?
    admin
    • Website

    Related Posts

    Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

    July 28, 2026

    Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

    July 28, 2026

    Funding gaps hobble western critical mineral objectives, report says

    July 28, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Hungary’s thawing relations with EU provide lucrative trade for foreign funds

    Can the New York Times Save Journalism From Our AI Overlords?

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    There’s a Way to Prevent Ovarian Cancer. Few Know About It.

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by