CISA Adds TeamCity Flaw to KEV as Ransomware Gangs Join Exploitation

CISA warns that ransomware gangs are now exploiting a critical JetBrains TeamCity authentication bypass vulnerability (CVE-2026-63077) patched in July. The flaw allows unauthenticated attackers to execute arbitrary OS commands. Shadowserver tracks over 160 unpatched exposed servers.
The authentication bypass exists in TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3, with attacks flowing through the agent polling protocol. Successful exploitation grants command execution at the privilege level of the server process, which can expose stored credentials, alter server state, and compromise build artifacts feeding downstream CI/CD pipelines.
This marks the fourth TeamCity vulnerability added to CISA's KEV catalog since October 2023, with each prior entry also linked to ransomware activity. Shadowserver's monitoring shows exposed unpatched servers have dropped from roughly 700 to about 160 since the July patch, though threat actors with state backing, including APT29, have historically targeted TeamCity deployments at scale.
Organizations running unpatched TeamCity servers could face severe operational disruption, as ransomware gangs may leverage the flaw to encrypt systems or steal credentials tied to software build processes. Because TeamCity sits at the center of CI/CD workflows, a compromise could ripple outward, potentially delaying product releases or tainting code artifacts at companies relying on the platform. Smaller DevOps teams with limited security staffing may be particularly exposed, and the pattern of repeated TeamCity exploitation suggests infrastructure-level attacks on software supply chains will likely continue.