<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400" -->

---
title: CISA: Ransomware gangs now exploiting critical TeamCity flaw
description: CISA has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077, a critical JetBrains TeamCity authentication bypass patched on July 25, as...
canonical: https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CISA: Ransomware gangs now exploiting critical TeamCity flaw | daily.dev
og:description: CISA has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077, a critical JetBrains TeamCity authentication bypass patched on July 25, as...
og:url: https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400
og:image: https://api.daily.dev/og/posts/IvpHb8400.png
og:image:alt: CISA: Ransomware gangs now exploiting critical TeamCity flaw
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA: Ransomware gangs now exploiting critical TeamCity flaw

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

CISA has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077, a critical JetBrains TeamCity authentication bypass patched on July 25, as now being actively exploited by ransomware gangs. The flaw allows unauthenticated attackers to execute arbitrary OS commands via the TeamCity agent polling protocol, potentially exposing credentials and compromising CI/CD pipelines. JetBrains confirmed in-the-wild exploitation on August 7. Shadowserver currently tracks roughly 160 unpatched internet-exposed TeamCity servers, down from 700 shortly after the patch. This marks the fourth TeamCity vulnerability since October 2023 tagged by CISA as exploited, all also abused in ransomware attacks. Administrators are urged to patch internet-facing servers immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw>

## Questions this post answers

### What is CVE-2026-63077 and how does it affect TeamCity On-Premises?

CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises that lets an unauthenticated attacker with HTTP(S) access exploit the agent polling protocol to bypass authentication and execute arbitrary OS commands with TeamCity server process privileges. JetBrains patched it on July 25 in versions 2025.11.7 and 2026.1.3. A successful attack can expose credentials, modify server state, and compromise CI/CD build artifacts.

_Teams running self-hosted CI/CD should track TeamCity patch status closely on daily.dev before the next incident hits._

### Is the TeamCity authentication bypass vulnerability being actively exploited by ransomware groups?

Yes, CISA updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077 as being abused in ransomware campaigns. JetBrains confirmed exploitation in the wild on August 7, sharing indicators of compromise. This is the fourth TeamCity vulnerability since October 2023 that CISA has tagged as exploited, and all four have also been abused in ransomware attacks.

_Security teams tracking active ransomware exploitation of dev tools can follow updates like this on daily.dev._

### How many TeamCity servers remain unpatched against CVE-2026-63077?

Security watchdog Shadowserver tracks just over 160 internet-exposed TeamCity servers still unpatched against CVE-2026-63077, down from an initial 700 exposed servers spotted right after the patch was released in July. JetBrains reports more than 30,000 DevOps teams use TeamCity, including at Citibank, Amazon Games, Tesla, and Samsung.

_Anyone patching exposed CI/CD infrastructure can keep tabs on exploitation trends like this via daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#cicd](https://daily.dev/tags/cicd), [#ransomware](https://daily.dev/tags/ransomware), [#jetbrains](https://daily.dev/tags/jetbrains)

[View this post on daily.dev](https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CISA: Ransomware gangs now exploiting critical TeamCity flaw","url":"https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400"},"datePublished":"2026-09-24T10:46:58.340Z","dateModified":"2026-09-24T11:11:57.836Z","description":"CISA has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077, a critical JetBrains TeamCity authentication bypass patched on July 25, as...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/619d4f79e9b3e784946247f4efc71f47?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/619d4f79e9b3e784946247f4efc71f47?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cicd,ransomware,jetbrains","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"CISA: Ransomware gangs now exploiting critical TeamCity flaw"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw-ivphb8400#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-63077 and how does it affect TeamCity On-Premises?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises that lets an unauthenticated attacker with HTTP(S) access exploit the agent polling protocol to bypass authentication and execute arbitrary OS commands with TeamCity server process privileges. JetBrains patched it on July 25 in versions 2025.11.7 and 2026.1.3. A successful attack can expose credentials, modify server state, and compromise CI/CD build artifacts. Teams running self-hosted CI/CD should track TeamCity patch status closely on daily.dev before the next incident hits."}},{"@type":"Question","name":"Is the TeamCity authentication bypass vulnerability being actively exploited by ransomware groups?","acceptedAnswer":{"@type":"Answer","text":"Yes, CISA updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077 as being abused in ransomware campaigns. JetBrains confirmed exploitation in the wild on August 7, sharing indicators of compromise. This is the fourth TeamCity vulnerability since October 2023 that CISA has tagged as exploited, and all four have also been abused in ransomware attacks. Security teams tracking active ransomware exploitation of dev tools can follow updates like this on daily.dev."}},{"@type":"Question","name":"How many TeamCity servers remain unpatched against CVE-2026-63077?","acceptedAnswer":{"@type":"Answer","text":"Security watchdog Shadowserver tracks just over 160 internet-exposed TeamCity servers still unpatched against CVE-2026-63077, down from an initial 700 exposed servers spotted right after the patch was released in July. JetBrains reports more than 30,000 DevOps teams use TeamCity, including at Citibank, Amazon Games, Tesla, and Samsung. Anyone patching exposed CI/CD infrastructure can keep tabs on exploitation trends like this via daily.dev."}}]}
```

