CISA warned that ransomware gangs are now exploiting a critical JetBrains TeamCity flaw, CVE-2026-63077, which allows unauthenticated attackers to bypass authentication and run arbitrary commands on affected servers. The issue has been added to CISAβs actively exploited catalog, and administrators are urged to patch exposed TeamCity systems immediately to protect CI/CD pipelines and stored credentials. #JetBrains #TeamCity #CVE-2026-63077 #CISA
Keypoints
- CISA says ransomware gangs are exploiting CVE-2026-63077 in JetBrains TeamCity.
- The flaw enables authentication bypass and remote command execution on the TeamCity server.
- JetBrains patched the vulnerability in TeamCity On-Premises versions 2025.11.7 and 2026.1.3.
- CISA added the issue to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to act quickly.
- More than 160 TeamCity servers remain unpatched and exposed online.