CISA warns ransomware gangs now exploiting critical JetBrains TeamCity vulnerability

Authentication bypass flaw patched in July is being abused in ongoing ransomware campaigns, federal agency says

By LineZotpaper
Published
Read Time2 min
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog to flag that ransomware gangs are now actively exploiting a critical authentication bypass vulnerability in JetBrains TeamCity, which was patched in late July.

CISA warned federal agencies on Wednesday that the vulnerability, tracked as CVE-2026-63077, is being abused in ransomware attacks. The flaw was patched by JetBrains on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. At the time, JetBrains described it as a critical authentication bypass that allows an unauthenticated attacker to execute arbitrary operating system commands on the TeamCity server via the agent polling protocol.

JetBrains confirmed on August 7 that the vulnerability was being exploited in the wild and shared indicators of compromise, urging customers who could not immediately patch to restrict access to trusted networks. CISA had already added the flaw to its Known Exploited Vulnerabilities catalog on August 5, ordering federal agencies to secure their networks within three days.

This marks the fourth TeamCity security issue since October 2023 that CISA has tagged as exploited in the wild and subsequently abused in ransomware campaigns.

Security monitoring organization Shadowserver is currently tracking just over 160 TeamCity servers that remain unpatched against the CVE-2026-63077 vulnerability.

§

Analysis

Why This Matters

  • A critical vulnerability in CI/CD infrastructure opens a direct path for ransomware attackers to compromise build pipelines, steal credentials, and deploy malicious artifacts downstream.
  • The flagging by CISA as ransomware-exploited signals that threat actors are actively weaponizing this flaw for financial extortion, increasing risk for organizations that have not yet patched.
  • With over 160 unpatched servers still exposed according to Shadowserver, the window for mitigation is narrowing.

Background

TeamCity is a widely used continuous integration and continuous delivery (CI/CD) server from JetBrains. Because these servers often have elevated privileges and access to source code repositories, deployment systems, and secrets, they are high-value targets for attackers. The current vulnerability (CVE-2026-63077) is an authentication bypass that can give an unauthenticated attacker full control of the server process. CISA has previously added three other TeamCity vulnerabilities to its catalog since October 2023, all of which were also exploited in ransomware campaigns, indicating a persistent pattern of attackers targeting this platform.

Key Perspectives

CISA: The agency is mandating that federal agencies remediate the vulnerability within three days of catalog addition and is publicly alerting all organizations to the active ransomware threat. JetBrains: The company patched the flaw in July and has provided indicators of compromise and guidance, but customers are responsible for applying updates. Security researchers and defenders: The Shadowserver data shows that while many organizations have patched, a significant tail of unpatched servers remains, representing attractive targets for ransomware gangs.

What to Watch

  • The number of unpatched TeamCity servers: a sharp decline would indicate effective mitigation, while stagnation suggests continued exposure.
  • Reports of ransomware incidents traced back to CVE-2026-63077 exploitation, which may emerge as incident response firms analyze breaches.
  • Whether JetBrains or CISA release additional detection guidance or forensic indicators as the campaigns evolve.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.