Technology · Jetbrains
Jetbrains TeamCity vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Jetbrains TeamCity: 0 in the last 7 days and 7 in the last 90 days, 5 of them critical and 4 exploited in the wild. The most recent, CVE-2026-63077, was published on 27 July 2026.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 5
- Exploited in the wild
- 4
About Jetbrains TeamCity
A continuous integration and continuous delivery server for automating software build, test, and deployment processes.
Latest Jetbrains TeamCity vulnerabilities
- CVE-2026-63077: JetBrains TeamCity remote code execution in agent polling protocolcriticalexploited in the wildCVSS 9.8EPSS 0.7%
- CVE-2026-65907: JetBrains TeamCity code execution in Git VCS rootscriticalCVSS 9.1
- CVE-2026-65906: JetBrains TeamCity remote code execution via Kotlin DSL sandbox escapehighCVSS 8.8
- CVE-2026-59796: JetBrains TeamCity improper permission checks in pipeline modificationhighCVSS 8.1
- CVE-2026-59795: JetBrains TeamCity stored XSS in agent registrationhighCVSS 8.1
- CVE-2026-59794: JetBrains TeamCity stored XSS in cloud profile pagehighCVSS 7.3
- CVE-2026-59793: JetBrains TeamCity arbitrary file access in Perforce VCS integrationhighCVSS 8.8
- CVE-2026-49381: JetBrains TeamCity stored XSS on SAML login pagelowCVSS 3.4
- CVE-2026-49380: JetBrains TeamCity open redirect in SAML pluginlowCVSS 3.1
- CVE-2026-49379: JetBrains TeamCity credential exposure in thread namesmediumCVSS 6.5
- CVE-2026-49378: JetBrains TeamCity credential exposure via parameter autocompletionmediumCVSS 4.3
- CVE-2026-49377: JetBrains TeamCity sensitive data exposure in default agent parametersmediumCVSS 4.3
- CVE-2026-49376: JetBrains TeamCity insufficient username validation in SAML pluginmediumCVSS 6.5
- CVE-2026-49375: JetBrains TeamCity reflected XSS in repository download pagemediumCVSS 6.1
- CVE-2026-49374: JetBrains TeamCity improper permission checks in build configurationhighCVSS 7.6
- CVE-2026-49373: JetBrains TeamCity remote code execution in Perforce connection settingshighCVSS 7.1
- CVE-2026-49372: JetBrains TeamCity unauthenticated SSRF in build statushighCVSS 7.5
- CVE-2026-49371: JetBrains TeamCity reflected XSS in keyword filterhighCVSS 7.1
- CVE-2026-44413: JetBrains TeamCity authentication bypass in server APIhighCVSS 8.2
- CVE-2024-27199: JetBrains TeamCity relative path traversal in admin interfacecriticalexploited in the wildCVSS 7.3EPSS 90.9%
- CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-42793: JetBrains TeamCity Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
Most severe Jetbrains TeamCity vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-63077: JetBrains TeamCity remote code execution in agent polling protocolcriticalexploited in the wildCVSS 9.8EPSS 0.7%
- CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-42793: JetBrains TeamCity Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-27199: JetBrains TeamCity relative path traversal in admin interfacecriticalexploited in the wildCVSS 7.3EPSS 90.9%
- CVE-2026-65907: JetBrains TeamCity code execution in Git VCS rootscriticalCVSS 9.1
- CVE-2026-65906: JetBrains TeamCity remote code execution via Kotlin DSL sandbox escapehighCVSS 8.8
- CVE-2026-59793: JetBrains TeamCity arbitrary file access in Perforce VCS integrationhighCVSS 8.8
- CVE-2026-44413: JetBrains TeamCity authentication bypass in server APIhighCVSS 8.2
- CVE-2026-59796: JetBrains TeamCity improper permission checks in pipeline modificationhighCVSS 8.1
- CVE-2026-59795: JetBrains TeamCity stored XSS in agent registrationhighCVSS 8.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 2 | 1 | |
| 27 Jul 2026 | 1 | 1 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/teamcity.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jetbrains TeamCity vulnerabilities", https://junglewise.ai/threats/technologies/teamcity, 26 September 2026.