CISA Flags TeamCity Vulnerability as Exploited by Ransomware Actors
According to BleepingComputer, CISA has flagged a vulnerability in JetBrains TeamCity as being exploited by ransomware actors. Fixes and a security patch are available.

TeamCity vulnerability CVE-2026-63077 is a serious warning for operators of on-premises installations of JetBrains’ CI/CD server. BleepingComputer reported that on September 23, 2026, CISA updated the entry for this flaw in its Known Exploited Vulnerabilities (KEV) catalog and flagged it as being exploited by ransomware actors.
JetBrains has released fixes for the critical vulnerability. It affects TeamCity On-Premises, while TeamCity Cloud does not require customer action, according to the vendor.
What the TeamCity CVE-2026-63077 vulnerability enables
CVE-2026-63077 allows an unauthenticated attacker with HTTP(S) access to a vulnerable server to bypass authentication and execute commands with the privileges of the server process. The attacker therefore does not need a valid user account if they can connect to the affected TeamCity server’s interface.
TeamCity is a CI/CD platform for automating software builds, testing, and deployment. Successful exploitation could lead to the theft of stored credentials, configuration changes, or compromise of the integrity of builds and subsequent software supply chains.
Ransomware exploitation increases the urgency of patching
Active exploitation of a critical flaw is a reason to respond quickly. The information that CISA, according to BleepingComputer, has also flagged it as being exploited by ransomware actors increases the priority, especially for internet-exposed TeamCity On-Premises installations.
The available materials do not publicly confirm the names of the ransomware groups involved, specific victims, the scope of the campaigns, or technical indicators of compromise. Direct, current confirmation of the CISA KEV entry could not be independently verified, so the claim of ransomware exploitation is attributed to CISA through the BleepingComputer article.
Available fixes and recommended steps
JetBrains fixed the flaw in TeamCity versions 2025.11.7 and 2026.1.3. A security patch is also available as a plugin for TeamCity 2017.1 and later.
- Verify whether the organization operates TeamCity On-Premises and whether its interface is accessible over HTTP(S).
- Update to TeamCity 2025.11.7 or 2026.1.3 as soon as possible.
- If updating is not yet possible, deploy the security patch plugin for TeamCity 2017.1 and later.
- Distinguish an on-premises installation from the TeamCity Cloud service, for which JetBrains does not indicate that customer action is required.
Administrators should monitor for any direct CISA details about the KEV entry and additional JetBrains guidance on forensic reviews of potentially compromised servers. Public indicators of compromise, attribution to specific groups, or confirmed incidents would also be relevant.
Sources
- JetBrains TeamCity Blog – Confirms the impact of CVE-2026-63077, affected TeamCity On-Premises versions, fixed versions, and the available patch plugin.
- BleepingComputer – Reports that on September 23, 2026, CISA flagged this vulnerability in KEV as being exploited by ransomware actors.
Verified and updated: 09/24/2026 15:22



