Skip to main content

CISA: Ransomware gangs now exploiting critical TeamCity flaw

0
Critical
Vulnerabilityransomware
Published: 09/24/2026 (09/24/2026, 10:42:37 UTC)
Source: Bleeping Computer

Description

A critical authentication bypass vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated attackers with HTTP(S) access to execute arbitrary operating system commands. This flaw was patched in July 2026 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Despite the patch, ransomware gangs are actively exploiting this vulnerability, as confirmed by CISA and JetBrains. The vulnerability enables attackers to bypass authentication via the TeamCity agent polling protocol, potentially compromising server data, configurations, credentials, and build artifacts. CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog and mandated federal agencies to patch within three days. Shadowserver reports over 160 unpatched Internet-exposed TeamCity servers remain vulnerable. JetBrains urges immediate patching or restricting access to trusted networks.

Affected software

Affected versions
>=2025.0.0 <2025.11.7>=2026.0.0 <2026.1.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 10:48:07 UTC

Technical Analysis

CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises versions 2025.11.7 and earlier and 2026.1.3 and earlier, patched on July 25, 2026. It allows unauthenticated attackers with HTTP(S) access to exploit the TeamCity agent polling protocol to bypass authentication and execute arbitrary OS commands with the privileges of the TeamCity server process. This can lead to exposure of data, credentials, modification of server state, and compromise of build artifacts and CI/CD pipelines. The vulnerability has been actively exploited in the wild since early August 2026, including by ransomware gangs. CISA has issued warnings and added the vulnerability to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to patch promptly. JetBrains has confirmed exploitation and provided indicators of compromise. Shadowserver tracks over 160 unpatched servers exposed online, down from 700 initially. The vulnerability is significant due to TeamCity's widespread use in DevOps environments.

Potential Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the TeamCity server process. This can lead to exposure of sensitive TeamCity data, configurations, stored credentials, modification of server state, and compromise of build artifacts and downstream CI/CD pipelines. The vulnerability is actively exploited by ransomware gangs, increasing the risk of ransomware attacks and operational disruption. Unpatched servers exposed to the Internet remain at risk.

Mitigation Recommendations

JetBrains released an official patch on July 25, 2026, for TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Immediate application of these patches is strongly recommended. For environments where immediate patching is not possible, JetBrains advises restricting TeamCity server access to trusted networks only. CISA has mandated U.S. federal agencies to patch within three days of the advisory. Monitoring vendor advisories for updates and applying patches promptly is critical to mitigate ongoing exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.71,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/","fetched":true,"fetchedAt":"2026-09-24T10:47:59.180Z","wordCount":678}

Threat ID: 6ab4ffdff7a7c5410636367d

Added to database: 09/24/2026, 10:47:59 UTC

Last enriched: 09/24/2026, 10:48:07 UTC

Last updated: 09/24/2026, 10:48:07 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses