JetBrains has disclosed a critical security vulnerability in its TeamCity On-Premises continuous integration and delivery (CI/CD) server software. The flaw, identified as an authentication bypass, could allow unauthenticated attackers to execute arbitrary code remotely on affected servers.
What happened
The vulnerability affects all versions of TeamCity On-Premises prior to the latest patched release. JetBrains issued a security advisory on 30 July 2026, warning users of the risk and urging immediate updates. No evidence has been presented that the flaw has been exploited in the wild, but the company has not ruled out the possibility of prior attacks.
The advisory provides minimal technical details about the vulnerability to prevent exploitation before users can apply patches. JetBrains has released a fixed version of TeamCity On-Premises, and administrators are advised to upgrade as soon as possible. The company has not disclosed whether cloud-based TeamCity instances are affected.
What we don't know yet
The specific mechanics of the authentication bypass remain undisclosed. JetBrains has not confirmed whether proof-of-concept exploits exist or if the vulnerability was discovered internally or reported by external researchers. The company also has not provided guidance on detecting potential exploitation attempts on unpatched systems.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 30 Jul 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No existing article covers this JetBrains TeamCity vulnerability.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=377 slug=jetbrains-patches-critical-teamcity-rce-vulnerability quick_read=1
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states the advisory was issued 'on 30 July 2026', but the source only says 'JetBrains is warning' on its publication date (30 July 2026). The source does not explicitly state the advisory was issued on that calendar date. Omit the specific date or clarify if the advisory date is confirmed.
- Style compliance: The standfirst uses 'on-prem' (hyphenated) while the body uses 'on-premises' (spelled out). Standardize to 'on-premises' for consistency with the source and industry terminology.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #9
- Linking related stories — Linked 1 relations from 321 candidates
- Publishing — Published jetbrains-patches-critical-teamcity-rce-vulnerability
- Mastodon — Posted https://mstdn.social/@hostingpaper/117011616980635890



Discussion · coming soon
Be the first to join the thread when community discussion launches.