What happened
JetBrains has issued an urgent advisory for on-premises TeamCity users after the discovery of CVE-2026-63077, a critical vulnerability scoring 9.8 on the CVSS scale that allows attackers to execute arbitrary operating system commands without any authentication. All on-premises versions of the CI/CD platform are affected, and fixes are available in releases 2025.11.7 and 2026.1.3. TeamCity Cloud deployments were patched separately and are no longer at risk. Separately, LG Electronics USA announced it will suspend smart TV applications on its webOS platform that silently convert users' televisions into residential proxy nodes, routing third-party internet traffic through consumers' home connections without their knowledge. The decision follows research showing that more than 42 percent of apps in the webOS store contained this behavior.
Why it matters for your business
TeamCity is widely used in enterprise software delivery pipelines, and an unauthenticated remote code execution flaw at this severity level means that any exposed on-premises instance is a potential entry point for ransomware, supply chain compromise, or data exfiltration — no credentials required. Engineering and DevOps leaders should treat this as a patch-now priority and audit network access controls around build infrastructure. The LG smart TV issue raises a different but equally serious concern: organizations that provision employee lounges, lobby displays, or conference room screens with consumer-grade smart TVs may unknowingly be allowing their corporate IP addresses to serve as proxy exit nodes for unknown third parties. Procurement and IT teams should review device policies and verify that smart TV platforms in company spaces are running updated, vetted firmware.
What to watch next
Security researchers typically publish proof-of-concept exploit code within days of a critical CVE disclosure, so TeamCity shops that have not yet upgraded face an increasingly narrow window before active exploitation becomes widespread. On the smart TV front, LG has not confirmed a firm enforcement deadline for the proxy app ban, leaving open questions about how thoroughly the webOS store will be audited and whether other smart TV platforms harbor similar issues. Both stories underscore a broader trend of attackers and opportunistic software vendors targeting infrastructure that organizations treat as lower-priority for security reviews.
