A Critical Flaw in TeamCity Exposes DevOps Teams to Ransomware Attacks
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that ransomware gangs are exploiting a critical vulnerability in JetBrains’ TeamCity, a popular Continuous Integration and Continuous Deployment (CI/CD) platform used by software developers and DevOps teams. The flaw, patched in July, allows attackers to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.
The vulnerability, tracked as CVE-2026-63077, was identified as a critical authentication bypass issue that could expose sensitive data, configurations, and credentials stored on the TeamCity server. According to CISA, an unauthenticated attacker could exploit this flaw via the TeamCity agent polling protocol to execute arbitrary operating system commands with the privileges of the TeamCity server process.
JetBrains, the company behind TeamCity, confirmed in July that the vulnerability was being exploited in the wild and provided indicators of compromise to its customers. The company also urged users who couldn’t patch their servers immediately to limit access to trusted networks. However, CISA has now revealed that ransomware gangs are actively exploiting this flaw.
This is not an isolated incident. Since October 2023, CISA has identified four TeamCity security issues as being exploited in the wild, all of which have been abused by ransomware attacks. The agency has also flagged several other vulnerabilities in popular software platforms, including VMware, WatchGuard, and Microsoft SharePoint, which have also been targeted by ransomware gangs.
The prevalence of ransomware attacks on TeamCity servers is a concern for DevOps teams and organizations that rely on the platform for building, testing, and deploying software code. With over 30,000 DevOps teams using TeamCity at high-profile companies such as Citibank, Amazon Games, Tesla, and Samsung, the potential impact of this vulnerability is significant.
IT administrators are advised to patch Internet-exposed servers immediately to prevent exploitation by ransomware gangs or state-backed hacking groups. CISA has also added CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog (KEV) and ordered US federal agencies to secure their networks against ongoing attacks within three days.
In conclusion, the recent discovery of a critical TeamCity vulnerability being exploited by ransomware gangs serves as a reminder of the importance of timely patching and security updates for software platforms. DevOps teams and organizations should prioritize securing their CI/CD pipelines and ensure that all Internet-exposed servers are up-to-date with the latest patches to prevent potential attacks.
As a practical takeaway, it’s essential to regularly review and update your organization’s security protocols and policies to address emerging threats and vulnerabilities. This includes staying informed about newly discovered exploits and vulnerabilities, applying security updates promptly, and limiting access to sensitive data and systems only to authorized personnel.
Source: Bleeping Computer — 2026-09-24