Trending: On-device modelsSearch
iHeartGeek
iTECH

TeamCity 2026.2.1 and 2026.1.5 land with 40-plus security fixes

JetBrains has shipped bug-fix updates for TeamCity On-Premises 2026.1 and 2026.2 that resolve more than 40 vulnerabilities between them, and is urging administrators to upgrade promptly.

JetBrains TeamCity product graphic: the JetBrains logo above large white text reading 'TeamCity' and 'Powerful CI/CD solution for modern DevOps teams' on a blue and cyan gradient background with a green glow

JetBrains has released two bug-fix updates for TeamCity On-Premises, covering the 2026.1 and 2026.2 lines. The company said on 5 October that the pair address more than 40 vulnerabilities between them, and recommends that administrators upgrade as soon as they can.

What is in the updates

As with previous maintenance releases, security work dominates the change list. Beyond the vulnerability fixes, TeamCity 2026.2.1 and 2026.1.5 resolve a handful of functional and performance problems: TFS projects failing to display diffs, Pipelines being unable to import YAML configuration files from a main repository branch, and MSBuildTools not being detected after the Visual Studio Build Tools 2026 September update. Full issue lists are published in the release notes for each version.

Upgrading, and why the version line matters

All bug-fix updates released for the same major version share a data format, so administrators can upgrade or downgrade within a series without taking a backup and restoring it first. JetBrains points to three routes: the automatic update feature inside a current TeamCity installation, a direct download from its website, or an updated Docker image. The company also advises reading the release notes before upgrading rather than pulling the image blind.

The security context

The urgency is not theoretical. JetBrains published a follow-up in August to its July advisory on CVE-2026-63077, after receiving reports of active exploitation, and attempted exploitation, of unpatched TeamCity servers. A server exposed to the internet with a known, unpatched vulnerability is one of the more reliable ways to lose a build pipeline, and TeamCity installations tend to hold the credentials, signing keys and deployment hooks for everything downstream. That is the case for treating a maintenance release with 40-plus security fixes as more than routine housekeeping.

Our opinion

Self-hosted build servers have a habit of being the least-updated thing in an organisation, for the very good reason that nobody wants to be the person who breaks the pipeline on a Friday. That instinct is what makes an advisory like this awkward: the fix is a routine bug-fix release that shares a data format with the version already running, so the upgrade path is genuinely low-risk, and yet the tools it protects are the ones with the keys to everything. The pattern JetBrains describes, where a July advisory escalates into August reports of exploitation in the wild, is the ordinary life cycle of a server-side flaw. Teams that run TeamCity on-premises should treat the 2026.1.5 and 2026.2.1 releases as a scheduled job rather than a project, because the alternative is discovering the value of a patched build server at the moment it stops being yours.