Cybersecurity experts are sounding the alarm as ransomware gangs have begun exploiting a critical vulnerability in JetBrains’ TeamCity platform. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that the attackers are taking advantage of a security flaw patched in July, raising concerns about the potential for widespread attacks on Internet-exposed servers.
The vulnerability, tracked as CVE-2026-63077, is an authentication bypass flaw that allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the TeamCity server process. This could expose sensitive data, modify server state, and potentially compromise build artifacts and downstream Continuous Integration/Continuous Deployment (CI/CD) pipelines.
JetBrains patched the issue on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, but it appears that some organizations have yet to take action. CISA added CVE-2026-63077 to its catalog of actively exploited vulnerabilities on August 5, ordering U.S. federal agencies to secure their networks against ongoing attacks within three days.
Since October 2023, CISA has tagged four TeamCity security issues as being exploited in the wild, all of which have also been used by ransomware gangs in attacks. Security threat watchdog Shadowserver is now tracking just over 160 unpatched Internet-exposed servers vulnerable to CVE-2026-63077.
TeamCity is a popular CI/CD platform used by software developers and DevOps teams to automate building, testing, and deploying code. JetBrains claims that more than 30,000 DevOps teams use TeamCity at high-profile companies including Citibank, Amazon Games, Tesla, and Samsung.
The fact that state-backed hacking groups and ransomware gangs have frequently leveraged TeamCity vulnerabilities in attacks makes it essential for IT administrators to patch Internet-exposed servers immediately. In October 2024, U.S. and U.K. cyber agencies warned that APT29 hackers linked to Russia’s Foreign Intelligence Service (SVR) were targeting vulnerable JetBrains TeamCity and Zimbra servers on a mass scale.
While CISA has not yet shared information about attacks targeting CVE-2026-63077 specifically, the warning is clear: unpatched Internet-exposed TeamCity servers are at significant risk of being exploited by ransomware gangs. It’s crucial for organizations to prioritize patching and take immediate action to protect themselves against potential attacks.
In practical terms, this means that IT administrators should review their server configurations and take steps to limit access to trusted networks if a patch cannot be applied immediately. Regularly updating dependencies and monitoring systems for signs of compromise can also help prevent attacks like these from succeeding in the first place.
Source: Bleeping Computer — 2026-09-24