Ransomware groups are exploiting a critical TeamCity On-Premises flaw

Ransomware operators are now exploiting CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw that can let an unauthenticated attacker run operating system commands on a vulnerable build server.

JetBrains disclosed CVE-2026-63077 in July 2026 and said the issue affects all TeamCity On-Premises versions. In that original advisory, the company said it was not aware of active exploitation at the time of publication. On August 7, JetBrains updated its guidance after receiving reports of active exploitation and attempted exploitation against unpatched TeamCity servers.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 5. BleepingComputer reported on September 24 that CISA had updated the catalog entry again to flag the flaw as being used in ransomware campaigns. Health-ISAC, through an American Hospital Association threat bulletin dated September 28, also warned that ransomware groups were exploiting the vulnerability.

Australia’s cyber agency, ASD’s ACSC, issued its own August 24 alert after observing active exploitation of TeamCity On-Premises servers within Australia. The agency said it had no information indicating a specific industry or sector was being targeted.

What CVE-2026-63077 allows

CVE-2026-63077 can be exploited without authentication when an attacker has HTTP or HTTPS access to a vulnerable TeamCity server. JetBrains says the attack path uses the TeamCity agent polling protocol and can allow arbitrary operating system commands to run with the privileges of the TeamCity server process.

JetBrains fixed the flaw in TeamCity 2025.11.7 and 2026.1.3. For environments that cannot upgrade immediately, JetBrains released a security patch plugin for TeamCity 2017.1 and later. The company has also said TeamCity Cloud customers do not need to take action because mitigations were already applied to the managed service.

Why CI/CD servers raise the stakes

TeamCity is a continuous integration and continuous delivery platform used to build, test, and deploy software. That role makes a vulnerable TeamCity server more sensitive than a typical exposed application server because it can sit near source code, deployment credentials, package registries, and release workflows.

JetBrains has warned that, depending on the privileges granted to the TeamCity process, successful exploitation could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise build artifacts and downstream CI/CD pipelines.

A separate JetBrains disclosure involving its Cadence service showed how broad the fallout from a TeamCity compromise can become. JetBrains said Cadence used TeamCity to orchestrate workloads, that the Cadence environment was vulnerable to CVE-2026-63077, and that attackers exploited the issue. JetBrains’ investigation found unauthorized access and potential exposure involving customer data, source code, credentials, backups, and cloud resources associated with Cadence use.

That Cadence incident was not described by JetBrains as a ransomware event.

What administrators should check now

JetBrains’ guidance points to immediate upgrade or mitigation first, followed by investigation for signs of attempted or successful exploitation. For organizations running TeamCity On-Premises, these checks take priority.

  • Version status: confirm that TeamCity On-Premises is running 2025.11.7, 2026.1.3, or a later fixed version, or that the security patch plugin has been installed.
  • Network exposure: restrict TeamCity access to trusted networks wherever possible, especially for internet-facing systems. JetBrains recommends temporarily restricting external access if mitigation cannot be applied immediately.
  • Server logs: review TeamCity server logs for com.thoughtworks.xstream.converters.ConversionException, which may indicate attempted or successful exploitation, and com.thoughtworks.xstream.security.ForbiddenClassException, which may indicate an exploit attempt blocked after patching.
  • Unauthorized agents: review unauthorized build agents for unexpected entries, especially names beginning with scan, as JetBrains says these may indicate attempted exploitation.
  • Secrets and build output: if exploitation is suspected, review credentials reachable by TeamCity, source repositories, package registries, deployment environments, and recent build artifacts for suspicious access or changes.

The broader TeamCity pattern

This is not the first time TeamCity vulnerabilities have attracted high-risk exploitation. In December 2023, CISA and partner agencies warned that Russian Foreign Intelligence Service-affiliated actors were exploiting CVE-2023-42793 at scale against JetBrains TeamCity servers. JetBrains’ December 2023 update also pointed customers to CISA indicators and detection guidance for that earlier vulnerability.

What is still unknown

CISA’s public ransomware label does not, by itself, identify which ransomware groups are exploiting CVE-2026-63077, which sectors are being hit, or how many organizations have been affected. Shadowserver exposure data cited by BleepingComputer suggested that just over 160 TeamCity servers remained unpatched against the flaw around the time of the ransomware warning, down from about 700 exposed vulnerable servers after the July fix became available.

For organizations that operate TeamCity On-Premises, the safest reading is that patch status alone is not enough if the server was exposed before mitigation.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email