CISA: Ransomware gangs now exploiting critical TeamCity flaw
Recorded: Sept. 24, 2026, 11:01 a.m.
| Original | Summarized |
CISA: Ransomware gangs now exploiting critical TeamCity flaw News Featured ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach New Windows Defender zero-day blocks Microsoft antivirus updates EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts Check Point warns of Management Server zero-day exploited in attacks Get AI-powered Autodesk AutoCAD for $399, save $1,696 CISA: Ransomware gangs now exploiting critical TeamCity flaw OpenAI hacked Australian Medicare govt site, probed data providers Microsoft fixes bug that broke Windows File History backup feature Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityCISA: Ransomware gangs now exploiting critical TeamCity flaw CISA: Ransomware gangs now exploiting critical TeamCity flaw By Sergiu Gatlan September 24, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. Unpatched TeamCity servers exposed online (Shadowserver) Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Actively Exploited Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Microsoft reminds admins to migrate Entra ID users to passkeys New Windows Defender zero-day blocks Microsoft antivirus updates Sponsor Posts Overdue a password health-check? Audit your Active Directory for free Automate Onboarding and Access Reviews with No-Code IGA: See how it works AI is a data-breach time bomb: Read the new report Overdue a password health-check? Audit your Active Directory for free Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to federal agencies indicating that ransomware gangs are actively exploiting a critical vulnerability within the JetBrains TeamCity platform. This concern stems from the flaw, tracked as CVE-2026-63077, which was patched by JetBrains on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. The vulnerability is categorized as a critical authentication bypass, enabling an unauthenticated attacker with HTTP(S) access to execute arbitrary operating system commands. Consequently, attackers could bypass authentication checks to gain privileges of the TeamCity server process, potentially exposing sensitive data, configurations, stored credentials, modifying the server state, and compromising the integrity of build artifacts and downstream continuous integration and continuous deployment pipelines. Almost two weeks after the patch, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog, highlighting that the flaw is being actively exploited. JetBrains confirmed that the vulnerability was exploited in the wild on August 7 and advised customers to limit access to trusted networks if immediate patching was not possible. Furthermore, CISA updated its catalog to flag this vulnerability as being abused by ransomware gangs, noting that since October 2023, the agency has tagged four TeamCity security issues as exploited in the wild, all linked to ransomware attacks. Security threat watchdog Shadowserver is currently tracking just over one hundred and sixty TeamCity servers that remain unpatched against this specific flaw, which underscores a significant remediation gap. TeamCity functions as a Continuous Integration and Continuous Deployment (CI/CD) platform essential for software developers and DevOps teams automating the building, testing, and deployment of code. Given that TeamCity is utilized by major organizations such as Citibank, Amazon Games, Tesla, and Samsung, the potential impact of a successful attack extends beyond a single system, threatening the integrity of critical software delivery processes across the enterprise. The widespread exposure of these platforms to state-backed hacking groups and ransomware gangs emphasizes the need for immediate action. Consequently, IT administrators are strongly advised to prioritize patching Internet-exposed servers running TeamCity to mitigate these systemic security risks. |