CISA: Ransomware gangs now exploiting critical TeamCity flaw
A critical authentication bypass vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated attackers with HTTP(S) access to execute arbitrary operating system commands. This flaw was patched in July 2026 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Despite the patch, ransomware gangs are actively exploiting this vulnerability, as confirmed by CISA and JetBrains. The vulnerability enables attackers to bypass authentication via the TeamCity agent polling protocol, potentially compromising server data, configurations, credentials, and build artifacts. CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog and mandated federal agencies to patch within three days. Shadowserver reports over 160 unpatched Internet-exposed TeamCity servers remain vulnerable. JetBrains urges immediate patching or restricting access to trusted networks.
AI Analysis
Technical Summary
CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises versions 2025.11.7 and earlier and 2026.1.3 and earlier, patched on July 25, 2026. It allows unauthenticated attackers with HTTP(S) access to exploit the TeamCity agent polling protocol to bypass authentication and execute arbitrary OS commands with the privileges of the TeamCity server process. This can lead to exposure of data, credentials, modification of server state, and compromise of build artifacts and CI/CD pipelines. The vulnerability has been actively exploited in the wild since early August 2026, including by ransomware gangs. CISA has issued warnings and added the vulnerability to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to patch promptly. JetBrains has confirmed exploitation and provided indicators of compromise. Shadowserver tracks over 160 unpatched servers exposed online, down from 700 initially. The vulnerability is significant due to TeamCity's widespread use in DevOps environments.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the TeamCity server process. This can lead to exposure of sensitive TeamCity data, configurations, stored credentials, modification of server state, and compromise of build artifacts and downstream CI/CD pipelines. The vulnerability is actively exploited by ransomware gangs, increasing the risk of ransomware attacks and operational disruption. Unpatched servers exposed to the Internet remain at risk.
Mitigation Recommendations
JetBrains released an official patch on July 25, 2026, for TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Immediate application of these patches is strongly recommended. For environments where immediate patching is not possible, JetBrains advises restricting TeamCity server access to trusted networks only. CISA has mandated U.S. federal agencies to patch within three days of the advisory. Monitoring vendor advisories for updates and applying patches promptly is critical to mitigate ongoing exploitation.
CISA: Ransomware gangs now exploiting critical TeamCity flaw
Description
A critical authentication bypass vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated attackers with HTTP(S) access to execute arbitrary operating system commands. This flaw was patched in July 2026 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Despite the patch, ransomware gangs are actively exploiting this vulnerability, as confirmed by CISA and JetBrains. The vulnerability enables attackers to bypass authentication via the TeamCity agent polling protocol, potentially compromising server data, configurations, credentials, and build artifacts. CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog and mandated federal agencies to patch within three days. Shadowserver reports over 160 unpatched Internet-exposed TeamCity servers remain vulnerable. JetBrains urges immediate patching or restricting access to trusted networks.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises versions 2025.11.7 and earlier and 2026.1.3 and earlier, patched on July 25, 2026. It allows unauthenticated attackers with HTTP(S) access to exploit the TeamCity agent polling protocol to bypass authentication and execute arbitrary OS commands with the privileges of the TeamCity server process. This can lead to exposure of data, credentials, modification of server state, and compromise of build artifacts and CI/CD pipelines. The vulnerability has been actively exploited in the wild since early August 2026, including by ransomware gangs. CISA has issued warnings and added the vulnerability to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to patch promptly. JetBrains has confirmed exploitation and provided indicators of compromise. Shadowserver tracks over 160 unpatched servers exposed online, down from 700 initially. The vulnerability is significant due to TeamCity's widespread use in DevOps environments.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the TeamCity server process. This can lead to exposure of sensitive TeamCity data, configurations, stored credentials, modification of server state, and compromise of build artifacts and downstream CI/CD pipelines. The vulnerability is actively exploited by ransomware gangs, increasing the risk of ransomware attacks and operational disruption. Unpatched servers exposed to the Internet remain at risk.
Mitigation Recommendations
JetBrains released an official patch on July 25, 2026, for TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Immediate application of these patches is strongly recommended. For environments where immediate patching is not possible, JetBrains advises restricting TeamCity server access to trusted networks only. CISA has mandated U.S. federal agencies to patch within three days of the advisory. Monitoring vendor advisories for updates and applying patches promptly is critical to mitigate ongoing exploitation.
Technical Details
- Classification
- {"confidence":0.71,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/","fetched":true,"fetchedAt":"2026-09-24T10:47:59.180Z","wordCount":678}
Threat ID: 6ab4ffdff7a7c5410636367d
Added to database: 09/24/2026, 10:47:59 UTC
Last enriched: 09/24/2026, 10:48:07 UTC
Last updated: 09/24/2026, 10:48:07 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.