The company has patched a critical pre-authentication flaw in TeamCity that could let attackers execute arbitrary commands, expose credentials, and compromise supply chains on self-hosted servers.