LmCast :: Stay tuned in

CISA: Ransomware gangs now exploiting critical TeamCity flaw

Recorded: Sept. 24, 2026, 11:01 a.m.

Original Summarized

CISA: Ransomware gangs now exploiting critical TeamCity flaw

News

Featured
Latest

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

New Windows Defender zero-day blocks Microsoft antivirus updates

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Check Point warns of Management Server zero-day exploited in attacks

Get AI-powered Autodesk AutoCAD for $399, save $1,696

CISA: Ransomware gangs now exploiting critical TeamCity flaw

OpenAI hacked Australian Medicare govt site, probed data providers

Microsoft fixes bug that broke Windows File History backup feature

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCISA: Ransomware gangs now exploiting critical TeamCity flaw

CISA: Ransomware gangs now exploiting critical TeamCity flaw

By Sergiu Gatlan

September 24, 2026
06:42 AM
0

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.
JetBrains patched the security flaw (tracked as CVE-2026-63077) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands.
"An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," it said.
"Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines."
Almost two weeks later, on August 5, CISA added CVE-2026-63077 to its catalog of actively exploited vulnerabilities and ordered U.S. federal agencies to secure their networks against ongoing attacks within three days.
JetBrains confirmed that the flaw was exploited in the wild on August 7, shared indicators of compromise, and urged customers who couldn't immediately patch their servers to limit access to trusted networks.
Now exploited in ransomware attacks
While CISA has not yet shared information about attacks targeting CVE-2026-63077, it updated its Known Exploited Vulnerabilities Catalog (KEV) again on Wednesday, flagging the vulnerability as being abused by ransomware gangs.
In total, since October 2023, the cybersecurity agency has tagged four TeamCity security issues as exploited in the wild, all of which have also been abused in ransomware attacks.
Security threat watchdog Shadowserver is now tracking just over 160 TeamCity servers unpatched against the CVE-2026-63077 flaw, down from an initial 700 Internet-exposed servers vulnerable to attacks spotted right after the vulnerability was patched.

Unpatched TeamCity servers exposed online (Shadowserver)
​Because state-backed hacking groups and ransomware gangs have often leveraged TeamCity vulnerabilities in attacks, IT administrators are advised to patch Internet-exposed servers immediately.
For instance, in October 2024, U.S. and U.K. cyber agencies warned that APT29 hackers linked to Russia's Foreign Intelligence Service (SVR) were targeting vulnerable JetBrains TeamCity and Zimbra servers "at a mass scale." 
TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) platform used by software developers and DevOps teams to automate building, testing, and deploying software code.
JetBrains says more than 30,000 DevOps teams use TeamCity at many high-profile companies, including Citibank, Amazon Games, Tesla, and Samsung.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
CISA: Critical VMware RCE flaw now exploited by ransomware gangsCISA: WatchGuard RCE flaw now exploited in ransomware attacksCISA: Microsoft SharePoint flaw now exploited in ransomware attacksCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayCISA orders urgent patching of actively exploited Zimbra flaw

Actively Exploited
CISA
JetBrains
Ransomware
RCE
Remote Code Execution
TeamCity

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Microsoft reminds admins to migrate Entra ID users to passkeys

New Windows Defender zero-day blocks Microsoft antivirus updates

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

AI is a data-breach time bomb: Read the new report

Overdue a password health-check? Audit your Active Directory for free

Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to federal agencies indicating that ransomware gangs are actively exploiting a critical vulnerability within the JetBrains TeamCity platform. This concern stems from the flaw, tracked as CVE-2026-63077, which was patched by JetBrains on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. The vulnerability is categorized as a critical authentication bypass, enabling an unauthenticated attacker with HTTP(S) access to execute arbitrary operating system commands. Consequently, attackers could bypass authentication checks to gain privileges of the TeamCity server process, potentially exposing sensitive data, configurations, stored credentials, modifying the server state, and compromising the integrity of build artifacts and downstream continuous integration and continuous deployment pipelines.

Almost two weeks after the patch, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog, highlighting that the flaw is being actively exploited. JetBrains confirmed that the vulnerability was exploited in the wild on August 7 and advised customers to limit access to trusted networks if immediate patching was not possible. Furthermore, CISA updated its catalog to flag this vulnerability as being abused by ransomware gangs, noting that since October 2023, the agency has tagged four TeamCity security issues as exploited in the wild, all linked to ransomware attacks. Security threat watchdog Shadowserver is currently tracking just over one hundred and sixty TeamCity servers that remain unpatched against this specific flaw, which underscores a significant remediation gap.

TeamCity functions as a Continuous Integration and Continuous Deployment (CI/CD) platform essential for software developers and DevOps teams automating the building, testing, and deployment of code. Given that TeamCity is utilized by major organizations such as Citibank, Amazon Games, Tesla, and Samsung, the potential impact of a successful attack extends beyond a single system, threatening the integrity of critical software delivery processes across the enterprise. The widespread exposure of these platforms to state-backed hacking groups and ransomware gangs emphasizes the need for immediate action. Consequently, IT administrators are strongly advised to prioritize patching Internet-exposed servers running TeamCity to mitigate these systemic security risks.