CISA FLAGS RANSOMWARE USE OF CRITICAL JETBRAINS TEAMCITY VULNERABILITY

A critical vulnerability in JetBrains TeamCity On-Premises is now known to be used in ransomware campaigns, according to an update to CISA’s Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-63077, gives organizations running unpatched TeamCity servers an urgent reason to update and investigate possible intrusion.

An attacker who can reach a vulnerable TeamCity server over HTTP or HTTPS could exploit the flaw without signing in. JetBrains says successful exploitation can bypass authentication and run operating system commands with the privileges of the TeamCity server process. Depending on those privileges, an attacker could access stored credentials or alter build artifacts and software delivery pipelines.

JetBrains had already reported active exploitation against unpatched servers before CISA updated its ransomware designation on September 23. CISA’s designation does not identify a particular ransomware group or disclose how many organizations were affected.

What TeamCity Administrators Should Do

Update TeamCity On-Premises to 2025.11.7, 2026.1.3, or a later fixed version. JetBrains also offers a security patch plugin for versions 2017.1 and later when an immediate upgrade is not possible. That plugin addresses CVE-2026-63077 specifically; JetBrains recommends upgrading to receive other security fixes. TeamCity Cloud customers do not need to take action for this vulnerability.

Administrators should review server logs and investigate unexpected unauthorized build agents. JetBrains says a ConversionException log entry may warrant investigation, although it does not prove exploitation by itself. Organizations unable to patch an internet-accessible server immediately should restrict external access until they can apply a fix.

Leave a Comment

Your email address will not be published. Required fields are marked *