JetBrains · TeamCity
Updated August 6, 2026
JetBrains TeamCity contains a deserialization of untrusted data vulnerability, allowing remote code execution via the agent polling protocol. This vulnerability poses a significant risk to organizations using TeamCity, as it can be exploited by unauthenticated attackers. Immediate attention is required to prevent potential attacks.
If left unpatched, this vulnerability can lead to complete system compromise, resulting in data breaches and lateral movement. Unauthenticated attackers can execute arbitrary code, gaining control over the system.
Apply the latest security patch to JetBrains TeamCity as soon as possible, and ensure all agents are updated to prevent exploitation. Monitor system logs for suspicious activity and consider implementing additional security measures, such as network segmentation and access controls.