BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: Ransomware Gangs Exploiting Critical TeamCity RCE Flaw CVE-2026-63077

The U.S. Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities information for CVE-2026-63077, indicating that the critical JetBrains TeamCity vulnerability is now associated with ransomware campaigns.

The development raises the urgency for organizations still running unpatched TeamCity On-Premises servers. JetBrains previously confirmed active exploitation of the vulnerability and released fixes in July.

What is confirmed

CVE-2026-63077 affects TeamCity On-Premises and can be exploited without authentication when an attacker can reach the TeamCity server over HTTP or HTTPS. JetBrains says an attacker can use the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating-system commands with the privileges of the TeamCity server process.

JetBrains previously reported active and attempted exploitation against unpatched servers. On September 24, BleepingComputer reported that CISA had revised its Known Exploited Vulnerabilities information to flag the vulnerability as being used in ransomware attacks.

Why TeamCity compromise is especially serious

TeamCity is a continuous integration and continuous delivery platform. A compromised server may expose project data, configurations and stored credentials. JetBrains also warns that exploitation could allow attackers to modify server state and potentially affect build artifacts and downstream CI/CD pipelines.

This means the risk can extend beyond the TeamCity server itself. Credentials available to build systems may provide access to source-code repositories, cloud environments, deployment infrastructure or other connected services.

Who is affected

JetBrains says the vulnerability affected TeamCity On-Premises versions before the fixes released in versions 2025.11.7 and 2026.1.3. TeamCity Cloud customers do not need to take action for this vulnerability because JetBrains applied the necessary protections to the hosted service.

Organizations should run a currently supported and patched TeamCity release. JetBrains lists TeamCity 2026.2 as the current release as of September 2026.

What administrators should do now

Patch exposed TeamCity servers

Organizations operating TeamCity On-Premises should update to a fixed, current version immediately. JetBrains also provides a security patch plugin for older supported installations when an immediate full upgrade is not possible.

Restrict network exposure

If an affected server cannot be patched immediately, JetBrains recommends temporarily restricting external access. Internet-facing TeamCity servers should be limited to trusted networks where possible, with VPN access or another security layer considered for administrative access.

Investigate for prior exploitation

Because exploitation was already occurring before the ransomware-use designation, administrators should not assume that applying a patch proves a previously exposed server was never compromised. JetBrains recommends reviewing TeamCity logs and checking unauthorized build agents for unexpected entries, including suspicious agent names beginning with scan.

Protect credentials and the software supply chain

If compromise is suspected, security teams should identify credentials and secrets accessible to the TeamCity server, rotate potentially exposed credentials, review connected source-code and cloud accounts, and validate build and deployment integrity before trusting affected pipelines.

What remains unknown

CISA has not publicly attributed the ransomware exploitation to a specific ransomware operation in the information reviewed by A3E Cyber. The number of organizations affected by ransomware attacks exploiting CVE-2026-63077 is also not established publicly. Those details should not be inferred from the confirmed exploitation warning.

Sources

BleepingComputer: CISA says ransomware gangs are exploiting critical TeamCity flaw

JetBrains: Critical Security Issue Affecting TeamCity On-Premises

JetBrains: Additional Guidance Following Reports of Active Exploitation

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment