The TeamCity builds in this security update shipped on 5 October 2026, and JetBrains isn't hedging about it. The announcement post says the releases "focus heavily on security issues, addressing over 40 vulnerabilities combined" and that "we strongly recommend upgrading as soon as possible." What you can't read yet is how bad any single fix is. No severities or CVE IDs for these two builds were public when we checked on 6 October, so the patch order below rests on JetBrains' wording and on what happened to the same product in July.
What JetBrains published on 5 October
Two builds, one per supported line. The TeamCity 2026.2.1 release notes say "41 security problems have been fixed," alongside 24 bug fixes and 2 performance fixes. The notes for 2026.1.5 say "27 security problems have been fixed."
| Release | Build | Date | Security fixes |
|---|---|---|---|
| 2026.2.1 | 239120 | 5 October 2026 | 41 |
| 2026.1.5 | 222949 | 5 October 2026 | 27 |
Don't add 41 and 27. They're per-build counts, and JetBrains' announcement describes the total as "over 40 vulnerabilities combined", so the two numbers aren't additive.
The post also lists ordinary fixes: TFS projects failing to display diffs, pipelines that couldn't import YAML configuration files from main repository branches, and MSBuildTools going undetected after the Visual Studio Build Tools 2026 September update. Nothing there changes the decision.
What is not published yet
JetBrains points readers to its Security Bulletin for the vulnerabilities themselves: "To learn more about fixed vulnerabilities directly related to TeamCity, check out our Security Bulletin." JetBrains' release notes say "Security bulletins are typically published few days after the release date."
When we checked JetBrains' fixed-issues bulletin on 6 October, no TeamCity row listed 2026.2.1 or 2026.1.5 under "Resolved In." The newest TeamCity rows covered 2026.2, 2026.1.4 and 2025.11.8, which are earlier releases.
So how bad is it? Unknown, and we won't guess. JetBrains has said nothing about exploitation of these fixes either. Until the bulletin catches up, "strongly recommend upgrading as soon as possible" is the only severity signal there is, and it's a strong one.
Why a CI server patch is a credentials decision
A TeamCity server usually holds source access and deploy credentials for everything it builds. That's our judgment, not a JetBrains statement, and it's why a CI server isn't patched like a wiki. What an attacker can reach through it is the question, and our audit checklist for CI privilege paths covers how wide that blast radius gets.
TeamCity gave us a fresh example this summer. On July 27, 2026, JetBrains advised on CVE-2026-63077, which it said "may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands." The July advisory adds that "All versions of TeamCity On-Premises are affected," with fixes in 2025.11.7 and 2026.1.3.
By August JetBrains had received reports of active exploitation. In JetBrains' August update: "Since our initial announcement on July 27, 2026, we have received reports of active exploitation, as well as attempted exploitation, targeting unpatched TeamCity servers." That's the precedent, and it belongs to CVE-2026-63077 only. Nothing published ties the October fixes to exploitation.
How to patch TeamCity 2026.2.1 or 2026.1.5
JetBrains' post covers only the 2026.2 and 2026.1 lines, and we haven't found a published upgrade path for older ones, so these steps don't cover them. We also kept to the level of the post: no UI click paths or command flags, because we didn't pull them from JetBrains' docs.
1. Check your version and pick the line
If you run 2026.2.x, the target is 2026.2.1. If you run 2026.1.x, it's 2026.1.5. On 2025.11 or older, the announcement doesn't give you a target, so read JetBrains' upgrade documentation before planning.
2. Take a backup first
This is our judgment. JetBrains says: "All TeamCity bug-fix updates released for the same major version share data format. As a result, you can upgrade or downgrade within this series without the need for backup and restoration." That makes a same-series rollback technically possible. A backup is still cheap insurance on the server that holds your deploy credentials.
3. Upgrade by one of the three routes
The post offers an automatic update from your current TeamCity, a download from the JetBrains website, or the updated TeamCity Docker image. Use whichever matches how you installed it.
4. Confirm the build number
After the restart, check that the server reports build 239120 (2026.2.1) or 222949 (2026.1.5). A server that came back up but still shows the old build hasn't been patched, however clean the restart looked.
5. Look for the July exploitation signs, then read the bulletin
If your server was reachable from the internet over the summer, check for what JetBrains named in its August update: the log message com.thoughtworks.xstream.converters.ConversionException, and unauthorized agents with names starting with scan. In our view, finding either on a server that ran an unpatched version means treating the credentials it stored as exposed and rotating them. Rotating tokens is easier when you know where they live, and auditing GitHub App installation tokens shows the inventory work. Then recheck the bulletin in a few days, when the 2026.2.1 and 2026.1.5 rows should appear, and read what each fix touches.
What this means for your patch window and your CI setup
Two decisions. First, the window. JetBrains strongly recommends upgrading as soon as possible, and it received reports of active exploitation of TeamCity servers this summer. Our judgment: if yours is reachable from the internet, schedule an emergency window this week rather than the next sprint, and don't wait for severity scores that may arrive days later. If it sits behind a VPN, you have a little more room, but not much.
Second, ownership. Running your own CI server means being first in line for every fix like this. TeamCity Cloud customers needed no action for CVE-2026-63077, because JetBrains said "the necessary mitigations have already been applied." JetBrains hasn't published an equivalent sentence for the October fixes. Whether hosting is worth it is a cost and risk call, and we have no figures for it.
For the other release deadlines on the same calendar, see Platform and language release notes: what breaks and what to fix, and compare how GitLab's September CI/CD security release handled the same self-hosted question.
FAQ
Do I have to upgrade TeamCity now?
JetBrains writes "we strongly recommend upgrading as soon as possible." It hasn't published severities for these fixes yet, so there's no basis for waiting on them. Treat an internet-reachable server as urgent.
Are the 2026.2.1 and 2026.1.5 fixes being exploited?
JetBrains hasn't said so. The exploited vulnerability is CVE-2026-63077, from July, fixed in 2025.11.7 and 2026.1.3. Check the bulletin once it lists the October builds.
Can I downgrade after upgrading?
Within a series, yes. JetBrains says updates for the same major version "share data format," so you can "upgrade or downgrade within this series without the need for backup and restoration." Our judgment is still to back up before you start.
Does this affect TeamCity Cloud?
For CVE-2026-63077, JetBrains said: "TeamCity Cloud customers do not need to take any action, as the necessary mitigations have already been applied." That sentence is about the July issue. We found no equivalent statement for the October fixes, so ask JetBrains before assuming.
