Skip to content
TrustList
News

TeamCity 2026.2.1 and 2026.1.5 fix more than 40 security issues

Editorial

By TrustList Editorial

JetBrains strongly recommends upgrading the self-hosted CI server. The release notes say 41 security problems are fixed in 2026.2.1, with the security bulletin to follow.

About TeamCity 2026.2.1 and 2026.1.5 fix more than 40 security issues

TeamCity 2026.2.1 and 2026.1.5 fix more than 40 security issues

5 October 2026: JetBrains has released TeamCity 2026.2.1 and 2026.1.5, two bug-fix updates for the on-premises edition that it says address more than 40 vulnerabilities between them. Because the updates carry so many security fixes, the company strongly recommends upgrading as soon as possible. The release notes for 2026.2.1 put its own count at 41 security problems fixed.

Not yet independently verified. JetBrains has not yet listed CVE numbers or severities for these fixes. The release notes say the separate security bulletin follows a few days after release. We will update this when it can be confirmed, and remove this note.

The blog post is dated 5 October. It gives no CVE identifiers, severity ratings or descriptions of the individual flaws. The 2026.2.1 release notes explain why: the security bulletin with those details is typically published a few days after the release date. Until it appears, a team cannot tell from the public record whether any of the 41 fixes is exploitable without a login.

What else is in the updates

Alongside the security work, JetBrains lists a few ordinary fixes: TFS projects that failed to display diffs, Pipelines that could not import YAML configuration files from a main repository branch, and MSBuild tools that went undetected after the Visual Studio Build Tools 2026 September update.

Which versions to move to

The updates apply to the 2026.1 and 2026.2 lines. JetBrains says all bug-fix updates for one major version share the same data format, so an instance can move up or down within the series without a backup and restore. The company offers three routes: the automatic update feature inside TeamCity, a download from the JetBrains website, or a pull of the updated Docker image.

Recent history behind the urgency

TeamCity On-Premises has been in the news for this reason before. In July JetBrains told customers to update to 2025.11.7 or 2026.1.3 to fix CVE-2026-63077, and in August it published further guidance after reports of active exploitation.

Build servers hold deployment credentials and signing keys, so a compromise reaches well beyond the server itself. Teams on either line can plan the upgrade now rather than wait for the bulletin.

Company profile on TrustList: JetBrains

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy