Ransomware Gangs Exploit Critical JetBrains TeamCity Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that ransomware gangs are exploiting a critical vulnerability in JetBrains TeamCity, a widely used continuous integration and continuous deployment (CI/CD) platform.
Tracked as CVE-2026-63077, the flaw is an authentication bypass vulnerability affecting on-premises TeamCity installations. JetBrains patched the issue on July 25 in TeamCity versions 2025.11.7 and 2026.1.3.
An unauthenticated attacker with HTTP(S) access can exploit the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.
“Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configuration, and stored credentials, modify server state, and compromise the integrity of build artifacts and downstream CI/CD pipelines.”
On August 5, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) Catalog. The agency ordered U.S. federal agencies to protect their networks from ongoing attacks within three days.
JetBrains confirmed on August 7 that the vulnerability had been exploited in the wild and shared indicators of compromise. The company urged customers who had not patched their servers to restrict access to trusted networks.
CVE-2026-63077 now linked to ransomware attacks
CISA has now identified CVE-2026-63077 as being used in ransomware campaigns. The vulnerability’s entry in the Known Exploited Vulnerabilities Catalog indicates that ransomware groups are exploiting the flaw.
Since October 2023, CISA has added four TeamCity security issues to its catalog. All four have also been exploited in ransomware attacks.
Security threat monitor Shadowserver is currently tracking more than 160 TeamCity servers that remain exposed and vulnerable to CVE-2026-63077 attacks. That number has fallen from approximately 700 Internet-exposed servers identified as vulnerable shortly after the security flaw was patched.
.jpg)
Administrators urged to patch exposed TeamCity servers
State-sponsored hacking groups and ransomware gangs frequently target vulnerabilities in TeamCity. IT administrators should immediately patch Internet-exposed servers and restrict access to trusted networks where possible.
In October 2024, U.S. and U.K. cybersecurity agencies warned that APT29 hackers associated with Russia’s Foreign Intelligence Service (SVR) were targeting vulnerable JetBrains TeamCity and Zimbra servers “at scale.”
TeamCity is a CI/CD platform used by software developers and DevOps teams to automate the building, testing, and deployment of software code.
According to JetBrains, more than 30,000 DevOps teams use TeamCity at well-known companies, including Citibank, Amazon Games, Tesla, and Samsung.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



