Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

CISA says ransomware gangs are exploiting a critical JetBrains TeamCity flaw

BleepingComputer reported that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are exploiting CVE-2026-63077, a critical authentication-bypass vulnerability in JetBrains TeamCity.

JetBrains patched the flaw on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. The company said an unauthenticated attacker with HTTP(S) access could use the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. A successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise build artifacts and downstream CI/CD pipelines.

CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog on August 5 and ordered U.S. federal agencies to secure their networks against ongoing attacks within three days. JetBrains confirmed exploitation in the wild on August 7, published indicators of compromise, and urged customers unable to patch immediately to limit access to trusted networks. CISA has not shared information about attacks targeting this CVE.

Shadowserver is tracking just over 160 unpatched TeamCity servers, down from an initial 700 Internet-exposed vulnerable servers. In October 2024, U.S. and U.K. cyber agencies also warned that APT29, linked to Russia’s Foreign Intelligence Service (SVR), was targeting vulnerable JetBrains TeamCity and Zimbra servers at a mass scale. JetBrains says more than 30,000 DevOps teams use TeamCity.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.