TeamCity has an unauthenticated RCE. CVE-2026-63077 is already being exploited, so yes, patching is urgent. Read the Bugstoday report
But here’s our problem with this story.
The vulnerability isn’t the scary part. TeamCity’s position is.
A CI/CD server can have access to source code, build agents, credentials and deployment systems. That’s a ridiculous amount of trust to place in one machine and then call it “internal”.
We think this is exactly where companies get vulnerability management wrong. They look at the CVE, see 9.8, patch it, close the ticket and move on.
We’d rather ask a different question:
If someone owns this server, what else do they own?
If the answer includes production credentials, deployment pipelines or privileged internal systems, you don’t have a TeamCity problem.
You have an architecture problem.
And that’s what makes this vulnerability interesting to us.
Bugstoday take: Patch TeamCity now. Then look at everything TeamCity can touch. The permissions around a vulnerable system can matter more than the vulnerability itself.
Today’s bugs. Tomorrow’s breaches.




