CISA Says Ransomware Gangs Are Now Exploiting Critical TeamCity Flaw in CI/CD Pipelines
Ransomware gangs are now abusing CVE-2026-63077, a critical unauthenticated RCE in JetBrains TeamCity On-Premises patched in July. Fixed versions are 2025.11.7 and 2026.1.3.

Ransomware crews have found their way into the build servers that assemble corporate software. CISA has updated its Known Exploited Vulnerabilities catalog to flag that a critical JetBrains TeamCity flaw is now being used in ransomware attacks.
The bug, CVE-2026-63077, affects TeamCity On-Premises. It lets an unauthenticated attacker with network access to the server run operating system commands as the TeamCity process. Analysts score it around 9.8 out of 10.
Why a build server is such a prize
TeamCity sits in the middle of a company's CI/CD pipeline. It holds deployment credentials, API tokens, and often code-signing material, and it touches every build that ships.
Get code execution there and an attacker can steal secrets, move deeper into the network, or tamper with what gets built. That makes it a natural staging point for ransomware.
The attack path abuses the agent polling protocol that TeamCity build agents use to talk to the server. According to SC Media, analysts tie it to unsafe deserialization, which lets a crafted request skip authentication entirely.
Patched in July, still hurting in September
The flaw itself is not new. JetBrains fixed the flaw on July 25 in TeamCity 2025.11.7 and 2026.1.3. CISA added it to the KEV catalog on August 5, and JetBrains later confirmed exploitation in the wild and published indicators of compromise.
The new part is the ransomware label. CISA has not publicly named which gangs are behind the attacks. What the flag does show is that two months after the patch, enough servers are still exposed to be worth a ransomware crew's time.
TeamCity Cloud customers are already covered by JetBrains. The risk sits with self-hosted servers. Admins who cannot upgrade right away can install a security patch plugin for older versions, though JetBrains recommends the full upgrade.
Patching does not evict an intruder
The fix closes the door but does nothing about anyone who walked through it earlier. Tokens and credentials stored on a server exposed between July and the upgrade should be rotated, and build logs reviewed against the JetBrains indicators.
TeamCity has a history here. Since October 2023, CISA has tagged four TeamCity vulnerabilities as exploited in the wild, and all four have also been abused by ransomware operators. It fits a broader pattern of edge and infrastructure software becoming the entry point, from WatchGuard Firebox appliances to JFrog Artifactory, another tool that lives inside the software supply chain.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free