MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-24 · via BleepingComputer

CISA Adds TeamCity Flaw to KEV as Ransomware Gangs Join Exploitation

Image via BleepingComputer
Image via BleepingComputer

CISA warns that ransomware gangs are now exploiting a critical JetBrains TeamCity authentication bypass vulnerability (CVE-2026-63077) patched in July. The flaw allows unauthenticated attackers to execute arbitrary OS commands. Shadowserver tracks over 160 unpatched exposed servers.

Expanded Detail

The authentication bypass exists in TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3, with attacks flowing through the agent polling protocol. Successful exploitation grants command execution at the privilege level of the server process, which can expose stored credentials, alter server state, and compromise build artifacts feeding downstream CI/CD pipelines.

This marks the fourth TeamCity vulnerability added to CISA's KEV catalog since October 2023, with each prior entry also linked to ransomware activity. Shadowserver's monitoring shows exposed unpatched servers have dropped from roughly 700 to about 160 since the July patch, though threat actors with state backing, including APT29, have historically targeted TeamCity deployments at scale.

Context

Organizations running unpatched TeamCity servers could face severe operational disruption, as ransomware gangs may leverage the flaw to encrypt systems or steal credentials tied to software build processes. Because TeamCity sits at the center of CI/CD workflows, a compromise could ripple outward, potentially delaying product releases or tainting code artifacts at companies relying on the platform. Smaller DevOps teams with limited security staffing may be particularly exposed, and the pattern of repeated TeamCity exploitation suggests infrastructure-level attacks on software supply chains will likely continue.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Roundcube Webmail Vulnerability Under Active Attack, Canadian Cyber Center Warns · Cybersecurity
WordPress zero-day under active attack as exploit chain moves to file writes · Cybersecurity
Check Point rushes hotfix for critical management server flaw under active exploitation · Cybersecurity
WordPress Core CSRF bug enables remote code execution via theme preview · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “CISA: Ransomware gangs now exploiting critical TeamCity flaw.” Browse more stories.