Affected Systems
JetBrains TeamCity On-Premises, all versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud instances already patched. Vulnerability exploitable via agent polling protocol with HTTP(S) access to TeamCity server.
Exploitation Status
No evidence of active exploitation in the wild as of disclosure (July 28, 2026). Vulnerability disclosed by Antoni Tremblay on July 10, 2026. Public PoC status unknown.
Business Impact
Unauthenticated attackers with network access to TeamCity servers can execute arbitrary OS commands with TeamCity server process privileges. Successful exploitation enables data exfiltration (TeamCity configurations, stored credentials, build artifacts), server state modification, and potential lateral movement. High risk for organizations with internet-facing TeamCity instances. CI/CD pipeline compromise could lead to supply chain attacks.
Urgency
🔴 Immediate
Recommended Actions
- Update TeamCity On-Premises to version 2025.11.7 or 2026.1.3 immediately
- If immediate upgrade is not possible, deploy the JetBrains security patch plugin for versions 2017.1 and later
- Restrict network access to TeamCity servers via VPN or firewall rules to trusted IP ranges only
- Review TeamCity server logs for suspicious authentication bypass attempts or unexpected agent polling activity since July 10, 2026
- Audit stored credentials and secrets in TeamCity; rotate if compromise is suspected
- Remove internet exposure of TeamCity login screens and REST API endpoints where possible
