CISA warned federal agencies on Wednesday that the vulnerability, tracked as CVE-2026-63077, is being abused in ransomware attacks. The flaw was patched by JetBrains on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. At the time, JetBrains described it as a critical authentication bypass that allows an unauthenticated attacker to execute arbitrary operating system commands on the TeamCity server via the agent polling protocol.
JetBrains confirmed on August 7 that the vulnerability was being exploited in the wild and shared indicators of compromise, urging customers who could not immediately patch to restrict access to trusted networks. CISA had already added the flaw to its Known Exploited Vulnerabilities catalog on August 5, ordering federal agencies to secure their networks within three days.
This marks the fourth TeamCity security issue since October 2023 that CISA has tagged as exploited in the wild and subsequently abused in ransomware campaigns.
Security monitoring organization Shadowserver is currently tracking just over 160 TeamCity servers that remain unpatched against the CVE-2026-63077 vulnerability.