{"id":205,"date":"2026-09-26T14:07:59","date_gmt":"2026-09-26T14:07:59","guid":{"rendered":"https:\/\/managedt.com\/blog\/cisa-warns-ransomware-gangs-exploiting-jetbrains-teamcity-vulnerability\/"},"modified":"2026-09-26T14:08:00","modified_gmt":"2026-09-26T14:08:00","slug":"cisa-warns-ransomware-gangs-exploiting-jetbrains-teamcity-vulnerability","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/cisa-warns-ransomware-gangs-exploiting-jetbrains-teamcity-vulnerability\/","title":{"rendered":"CISA warns ransomware gangs are now exploiting critical JetBrains TeamCity vulnerability"},"content":{"rendered":"<p>Readers running JetBrains TeamCity servers now have a clear, actionable warning: a critical authentication bypass vulnerability, tracked as CVE-2026-63077, is being actively exploited by ransomware gangs. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, flagging it as abused in ransomware attacks and putting federal civilian agencies on a short fuse to secure their networks.<\/p>\n<h2>What is the vulnerability?<\/h2>\n<p>CVE-2026-63077 is a critical authentication bypass in JetBrains TeamCity On-Premises that lets an attacker who already has HTTP(S) access reach a server and execute arbitrary operating system commands. The flaw lives in the TeamCity agent polling protocol, which is the channel build agents use to check in with the server and pick up work. Because authentication checks can be bypassed through that protocol, the attacker does not need valid credentials. Once inside, the attacker runs code with whatever privileges the TeamCity server process holds.<\/p>\n<p>From there, the blast radius extends well past the TeamCity box itself. The same advisory warns that a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and undermine the integrity of build artifacts and anything downstream of the CI\/CD pipeline that consumes them.<\/p>\n<h2>When was it patched, and when did exploitation start?<\/h2>\n<p>JetBrains shipped a fix on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. CISA added the CVE to its KEV catalog on August 5 and ordered U.S. federal civilian agencies to remediate within three days. JetBrains confirmed exploitation in the wild on August 7 and released indicators of compromise, urging any customer unable to patch right away to restrict TeamCity access to trusted networks only.<\/p>\n<p>The Wednesday KEV update is what changed the picture. Up to that point, CISA had not publicly tied the flaw to ransomware activity. The new entry classifies CVE-2026-63077 as being abused by ransomware gangs, putting it alongside three other TeamCity vulnerabilities CISA has tracked as exploited in the wild since October 2023, all of which have also been used in ransomware attacks.<\/p>\n<h2>How many servers are still exposed?<\/h2>\n<p>The Shadowserver Foundation, a nonprofit that scans the internet for vulnerable systems, is tracking just over 160 TeamCity servers still unpatched against CVE-2026-63077 and reachable from the public internet. That number has dropped from roughly 700 servers Shadowserver counted right after the patch shipped, but any server still on the list is now a known target for ransomware operators.<\/p>\n<h2>Why TeamCity keeps attracting attackers<\/h2>\n<p>TeamCity is a Continuous Integration and Continuous Deployment (CI\/CD) platform used by software developers and DevOps teams to automate building, testing, and deploying code. JetBrains reports that more than 30,000 DevOps teams use TeamCity, including teams at Citibank, Amazon Games, Tesla, and Samsung. A compromise at the build server level gives attackers a foothold into source code, signing material, credentials, and the artifacts that flow into production systems, which is why state-sponsored groups and financially motivated criminals keep coming back to it.<\/p>\n<p>In October 2024, CISA and the U.K.&#8217;s cyber authorities warned that APT29, a hacking group linked to Russia&#8217;s Foreign Intelligence Service (SVR), was targeting vulnerable JetBrains TeamCity and Zimbra servers &#8220;at a mass scale.&#8221; That history is part of why the current KEV listing for ransomware activity carries extra weight: the same category of server has been hit by both espionage and criminal actors in the past 18 months.<\/p>\n<h2>What should administrators do now?<\/h2>\n<p>The core remediation is straightforward: patch internet-exposed TeamCity servers to 2025.11.7 or 2026.1.3 immediately. For organizations that cannot apply the update on the spot, JetBrains&#8217; guidance is to limit access to trusted networks until the patch lands, which closes off the agent polling protocol from the open internet and removes the easiest path to the bypass. CISA&#8217;s federal deadline of three days from KEV listing gives a useful internal SLA for anyone running TeamCity in production.<\/p>\n<p>Beyond patching, it is worth checking TeamCity logs and network telemetry for the indicators of compromise JetBrains released on August 7, since ransomware operators who land on an unpatched server tend to move quickly from initial access to credential theft and lateral movement.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-63077?<\/h3>\n<p>CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises. An unauthenticated attacker can exploit it through the TeamCity agent polling protocol to bypass authentication checks and run arbitrary operating system commands with the privileges of the TeamCity server process.<\/p>\n<h3>Which TeamCity versions fix the flaw?<\/h3>\n<p>JetBrains patched the vulnerability on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Servers running earlier versions and reachable from the internet remain vulnerable.<\/p>\n<h3>How many TeamCity servers are still exposed to this flaw?<\/h3>\n<p>Shadowserver is tracking just over 160 TeamCity servers on the public internet that remain unpatched against CVE-2026-63077, down from around 700 right after the patch was released.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-63077?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises. An unauthenticated attacker can exploit it through the TeamCity agent polling protocol to bypass authentication checks and run arbitrary operating system commands with the privileges of the TeamCity server process.\"}},{\"@type\":\"Question\",\"name\":\"Which TeamCity versions fix the flaw?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"JetBrains patched the vulnerability on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. Servers running earlier versions and reachable from the internet remain vulnerable.\"}},{\"@type\":\"Question\",\"name\":\"How many TeamCity servers are still exposed to this flaw?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Shadowserver is tracking just over 160 TeamCity servers on the public internet that remain unpatched against CVE-2026-63077, down from around 700 right after the patch was released.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA added a critical JetBrains TeamCity authentication bypass flaw to its Known Exploited Vulnerabilities Catalog after confirming ransomware gangs are<\/p>\n","protected":false},"author":3,"featured_media":204,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=205"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/205\/revisions"}],"predecessor-version":[{"id":206,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/205\/revisions\/206"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/204"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}