Your company's software update tool might have a serious security hole, and fixing it is urgent.

JetBrains, a company that makes tools for software developers, has found a major problem in one of its popular products called TeamCity. Specifically, this issue affects companies that use TeamCity "on-premises" [installed on their own computers, not in the cloud]. It's a critical security flaw that could let bad actors take control of a system without even needing a password.

Think of it like this: Imagine you have a smart home system that controls your lights, thermostat, and locks. This flaw is like someone discovering a hidden backdoor that lets them walk right into your house and change settings, or even lock you out, without ever needing your unique key or password. They wouldn't even leave a trace that they were there.

This "vulnerability" [a weakness in software that can be exploited] is technically known as CVE-2026-63077 and has a severity score of 9.8 out of 10, which is extremely high. It basically means someone could run their own commands on the affected computer, doing pretty much anything they want. This affects all versions of TeamCity On-Premises.

Why does this matter? TeamCity is often used by development teams to manage how they build and release software, a process called "continuous integration/continuous delivery" [CI/CD]. If an attacker gains control of a TeamCity server, they could potentially inject malicious code into the software being developed, steal sensitive company data, or disrupt operations entirely. It's a direct path to the heart of a company's software creation process.

The good news is that JetBrains has already fixed the problem. They released updates for TeamCity On-Premises, specifically versions 2025.11.7 and 2026.1.3, that close this backdoor. If your company uses TeamCity Cloud, you don't need to do anything, as JetBrains has already handled those updates for you.

This incident highlights a recurring theme in cybersecurity: even the tools designed to help build secure software can have their own vulnerabilities. For companies using TeamCity On-Premises, the immediate and most crucial step is to update their systems to the latest patched versions. Don't delay, as unpatched systems are prime targets for attackers looking for easy entry points.

If your organization uses TeamCity On-Premises, update it now to protect your systems from potential attacks.