
JetBrains has released an urgent security patch for TeamCity, warning that a critical vulnerability allows unauthorized actors to gain administrative access and execute malicious code.
The flaw is rated critical because it requires little to no prior authentication, potentially exposing sensitive build credentials, SSH keys, and passwords stored on servers.
Administrators are advised to immediately upgrade to the patched version and review authentication logs for suspicious activity, such as unauthorized account changes or unexpected plugins.