SummaryA critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077. For those who are unable to do so, we have released a security patch plugin. If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. We have also released a security patch plugin for 2017.1+ so that customers who are unable to upgrade can still patch their environments. Mitigation option 1: Update your server to 2025.11.7 or 2026.1.3To update your TeamCity server, download and install the latest patched version (2025.11.7 or 2026.1.3) or use the automatic update option within TeamCity.