CISA Warns Ransomware Gangs Now Exploiting Critical JetBrains TeamCity Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns federal agencies that ransomware gangs are now exploiting a critical authentication bypass flaw in JetBrains TeamCity On-Premises, tracked as CVE-2026-63077. JetBrains patched the vulnerability on July 25 in versions 2025.11.7 and 2026.1.3, explaining that unauthenticated attackers with HTTP(S) access can abuse the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.

A successful attack can expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on August 5 and ordered federal agencies to secure their networks within three days. JetBrains confirmed exploitation in the wild on August 7, shared indicators of compromise, and urged customers who cannot patch immediately to restrict access to trusted networks.

With Wednesday's update, CISA flags the vulnerability as abused in ransomware attacks, marking the fourth TeamCity issue since October 2023 that the agency links to ransomware activity. Security watchdog Shadowserver tracks just over 160 TeamCity servers still unpatched, down from an initial 700 internet-exposed vulnerable servers spotted shortly after the patch. Because both state-backed hacking groups and ransomware gangs frequently target TeamCity flaws, administrators are urged to patch internet-exposed servers immediately.

Read More at the original source →