Written by • 10:42 am• Blog

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednes…
CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.

JetBrains patched the security flaw (tracked as CVE-2026-63077) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands.

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” it said.

“Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines.”

Almost two weeks later, on August 5, CISA added CVE-2026-63077 to its catalog of actively exploited vulnerabilities and ordered U.S. federal agencies to secure their networks against ongoing attacks within three days.

JetBrains confirmed that the flaw was exploited in the wild on August 7, shared indicators of compromise, and urged customers who couldn’t immediately patch their servers to limit access to trusted networks.

Now exploited in ransomware attacks

While CISA has not yet shared information about attacks targeting CVE-2026-63077, it updated its Known Exploited Vulnerabilities Catalog (KEV) again on Wednesday, flagging the vulnerability as being abused by ransomware gangs.

In total, since October 2023, the cybersecurity agency has tagged four TeamCity security issues as exploited in the wild, all of which have also been abused in ransomware attacks.

Security threat watchdog Shadowserver is now tracking just over 160 TeamCity servers unpatched against the CVE-2026-63077 flaw, down from an initial 700 Internet-exposed servers vulnerable to attacks spotted right after the vulnerability was patched.

Unpatched TeamCity servers exposed online (Shadowserver)

​Because state-backed hacking groups and ransomware gangs have often leveraged TeamCity vulnerabilities in attacks, IT administrators are advised to patch Internet-exposed servers immediately.

For instance, in October 2024, U.S. and U.K. cyber agencies warned that APT29 hackers linked to Russia’s Foreign Intelligence Service (SVR) were targeting vulnerable JetBrains TeamCity and Zimbra servers “at a mass scale.” 

TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) platform used by software developers and DevOps teams to automate building, testing, and deploying software code.

JetBrains says more than 30,000 DevOps teams use TeamCity at many high-profile companies, including Citibank, Amazon Games, Tesla, and Samsung.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Article Source

↑
Close