Ransomware Hits JetBrains TeamCity Flaw: CVE-2026-63077 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A critical remote-code-execution flaw in JetBrains TeamCity, the continuous-integration platform used by more than 30,000 development teams worldwide, is now under active exploitation by ransomware crews, the Cybersecurity and Infrastructure Security Agency confirmed on September 23, 2026. The bug, tracked as CVE-2026-63077, carries a CVSS v3.1 score of 9.8 out of 10 and lets an unauthenticated attacker with network access to a vulnerable server run arbitrary operating-system commands with the privileges of the TeamCity process itself. JetBrains shipped a fix on July 25, 2026. Two months later, attackers are still finding unpatched servers to break into.

The timing matters. TeamCity sits at the center of software supply chains, orchestrating builds, running deployment pipelines, and holding credentials for cloud infrastructure. A successful breach does not just hand an intruder one server, it potentially hands them the keys to every downstream system the build pipeline touches. That is exactly what happened to JetBrains’ own Cadence environments in early September, when attackers used CVE-2026-63077 to extract AWS credentials, according to a report published by The Hacker News on September 5, 2026.

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What CVE-2026-63077 actually does

The flaw is classified as a deserialization-of-untrusted-data vulnerability that reaches the server through TeamCity’s agent polling protocol. JetBrains described the mechanism plainly in its July 25 advisory: an unauthenticated attacker with HTTP or HTTPS access to a TeamCity server can bypass authentication checks and execute arbitrary operating-system commands with the privileges of the TeamCity server process. No login, no stolen credentials, no social engineering required. Just network reachability to the server’s web interface.

The published CVSS vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, tells the same story in shorthand: attack vector is network-based, attack complexity is low, no privileges are required, no user interaction is needed, and the impact to confidentiality, integrity, and availability is all rated high. That combination is why the score lands at 9.8 rather than somewhere in the 7s or 8s where most “critical” bugs sit. Security researchers tend to treat a 9.8 unauthenticated RCE the same way a surgeon treats a severed artery: it does not wait.

Affected versions span the entire TeamCity On-Premises product line up to the patch point: 2025.11.6 and earlier, and 2026.1.2 and earlier. JetBrains closed the hole in versions 2025.11.7 and 2026.1.3. Cloud-hosted TeamCity customers were not affected, since JetBrains patches hosted instances centrally, but every organization running TeamCity on its own infrastructure, which is most large engineering shops that use the tool, needed to act on its own.

The timeline: patched in July, exploited by September

The gap between disclosure and exploitation is the part that should worry security teams most. Here is how the eight weeks unfolded, based on JetBrains’ own advisories, the official CVE.org record, and BleepingComputer’s reporting on CISA’s published vulnerability catalog entries.

DateEvent
July 10, 2026Vulnerability privately reported to JetBrains
July 25, 2026JetBrains ships patched versions 2025.11.7 and 2026.1.3
July 30, 2026BleepingComputer publishes first public writeup of the flaw
August 5, 2026CISA adds CVE-2026-63077 to the Known Exploited Vulnerabilities catalog
August 8, 2026Federal civilian agency remediation deadline under BOD 22-01
Early September 2026Attackers breach JetBrains’ own Cadence environments, extract AWS credentials
Late September 2026Exploitation volume increases; CISA explicitly ties the flaw to ransomware campaigns
September 23, 2026CISA issues formal warning that ransomware gangs are actively exploiting the flaw

Sixteen days passed between the patch shipping and CISA’s KEV listing. Roughly five weeks after that, JetBrains itself became a visible casualty, an irony that was not lost on security researchers covering the story. A vendor advisory and a federal remediation deadline did not stop exploitation from climbing through September. That pattern, patch early, exploit late, is becoming the default lifecycle for enterprise infrastructure flaws rather than the exception.

Why ransomware gangs want your CI/CD server

Ransomware operators used to go straight for file servers and domain controllers. Increasingly they go for the build pipeline first, because a CI/CD server like TeamCity is a force multiplier. It typically holds service account credentials, API tokens for cloud providers, signing keys for software releases, and direct network paths into production environments. Breach one TeamCity instance and an attacker can often move laterally into AWS, Azure, or GCP accounts, poison build artifacts before they ship to customers, or simply use the server as a beachhead to stage a ransomware payload across the entire corporate network.

That is effectively what happened inside JetBrains’ own Cadence environment. Attackers did not stop at compromising a build server, according to The Hacker News, they pulled AWS credentials out of it, turning a software vulnerability into a cloud-account intrusion in a single step. For a ransomware affiliate running an initial-access-broker playbook, that one pivot can be worth more than weeks of phishing.

CISA’s September 23 advisory described exploitation occurring in ransomware campaigns without naming a specific group, which is common in early-stage advisories where attribution is still being worked by multiple incident response firms simultaneously. The absence of a named gang does not mean the activity is small-scale. It usually means several groups, or several affiliates of a ransomware-as-a-service operation, are testing the same exploit in parallel before any one of them claims a high-profile victim, a dynamic that played out earlier this year when law enforcement dismantled one such operation and arrested its teenage operator.

JetBrains Cadence: when the vendor becomes the victim

The most uncomfortable detail in this entire story is that JetBrains itself, the company that builds TeamCity, had Cadence environments breached through the very vulnerability it had already patched. The Hacker News reported on September 5, 2026 that attackers exploited an unpatched instance to pull AWS credentials out of the environment. The deserialization bug allowed an unauthenticated attacker with access to a TeamCity server to bypass authentication and execute commands, exactly as described in the original advisory.

It is a useful reminder that “the vendor patched it” and “the instance is patched” are two different facts. Large organizations, including software vendors with dedicated security teams, routinely run multiple TeamCity instances across different business units, and patch rollout across a sprawling internal fleet rarely finishes on day one. If a company that builds the product can miss an instance, the odds that a mid-size engineering org with three TeamCity servers and a lean DevOps team has fully patched by now are not great.

Competitive comparison: how this stacks up against other CI/CD and edge-device flaws in 2026

CVE-2026-63077 does not exist in isolation. It is the latest in a run of critical, unauthenticated, remotely exploitable flaws that CISA has added to its Known Exploited Vulnerabilities catalog through the back half of 2026. Comparing it against other entries from the same period helps explain why ransomware actors keep finding new infrastructure targets rather than running out of options.

VulnerabilityProductCVSSAuth requiredPrimary exploitation path
CVE-2026-63077JetBrains TeamCity On-Premises9.8NoCI/CD pipeline, cloud credential theft
CVE-2026-83548SonicWall SMA 1000 Series10.0NoPre-auth SSRF, Workplace interface
CVE-2024-40766 (2025 Akira wave)SonicWall Gen 7 firewalls / SonicOS9.8NoSSL VPN access control bypass
CVE-2026-104286Fortinet FortiMail9.8NoPath traversal, arbitrary file write

Two of those rows are not hypothetical reference points, they are active CISA deadlines running in parallel with the TeamCity crisis. The agency gave federal agencies a short window to patch the FortiMail zero-day, and a similarly tight clock applies to the Citrix NetScaler zero-day that surfaced in the same stretch of early October. Security teams juggling all three KEV entries at once are not dealing with an isolated incident, they are dealing with a backlog.

The SonicWall comparison is especially instructive because it is the closest precedent to what is unfolding with TeamCity. In 2025, Akira ransomware affiliates, sometimes working alongside the Fog ransomware group, abused CVE-2024-40766 in SonicWall’s SonicOS to compromise more than 100 organizations between September and December of that year, according to reporting by The Register. Some of those intrusions went from initial VPN login to full network encryption in under 10 hours. SonicWall’s own product notice noted the renewed activity traced back to a flaw that had been public for roughly a year, not a fresh zero-day, which meant the real failure was patching cadence rather than detection.

CVE-2026-83548, disclosed by SonicWall in September 2026, raises the stakes further with a perfect 10.0 CVSS score, a pre-authentication server-side request forgery in the SMA 1000 Series Workplace interface that SonicWall confirmed was being actively exploited in the wild. No ransomware group has been publicly tied to it yet, but the pattern from 2025 suggests that window will not stay open for long. Edge devices and build servers are starting to look, from an attacker’s perspective, functionally interchangeable: both offer privileged access with minimal authentication friction.

Historical context: the slow shift from endpoints to infrastructure

Ransomware economics have changed shape over the past five years. Early campaigns relied heavily on phishing emails to land an initial foothold on a single workstation, then spent days or weeks moving laterally to reach anything valuable. That approach still works, but it is slow and noisy, and endpoint detection has gotten considerably better at catching it mid-chain.

Exploiting internet-facing infrastructure, VPN appliances, firewalls, file-transfer tools, and now CI/CD servers, skips most of that work. One unauthenticated request against an unpatched TeamCity server can deliver the same level of access that used to take a multi-stage phishing and lateral-movement campaign to achieve. The MOVEit file-transfer breaches of 2023, the wave of Citrix and Ivanti VPN exploitation through 2024 and 2025, and the Akira-SonicWall campaigns all follow the same arc: find a piece of perimeter or pipeline software that is trusted by default, hit it before patches roll out everywhere, and skip straight to the valuable part of the network.

TeamCity’s role in that arc is new territory in one specific sense. VPN appliances and file-transfer tools sit at the network edge by design. CI/CD servers usually sit deeper inside the network, closer to source code and cloud credentials, which is exactly why a breach there tends to produce outsized consequences, as JetBrains’ own Cadence incident demonstrated. The pattern lines up with a broader trend documented in recent ransomware data-theft reporting, where attackers increasingly prioritize stealing data over encrypting it outright, since stolen source code and credentials carry extortion value long after any ransom deadline passes. Remote-access tools have faced the same scrutiny: a recent round of TeamViewer patches addressed comparable authentication-bypass risk in widely deployed remote-support software.

Which industries face the most exposure

Not every organization running TeamCity carries the same risk profile. Financial services firms, healthcare technology vendors, and SaaS companies that ship frequent releases tend to run the largest, most interconnected TeamCity deployments, often with dozens of build configurations feeding dozens of cloud environments. Those are also the organizations where a compromised build server can reach the most downstream systems in one hop, because mature CI/CD setups are built precisely to maximize automation and minimize manual gatekeeping between code and production.

Smaller engineering teams are not off the hook either. A startup running a single, internet-facing TeamCity instance with broad AWS permissions attached to its deploy keys can be just as attractive a target as a larger enterprise, and often has fewer resources dedicated to patch management or network segmentation. Ransomware affiliates scanning for exposed TeamCity instances are not filtering by company size, they are filtering by whether port 8111 or the default web interface responds to an unauthenticated request.

How JetBrains’ security response compares to rival CI/CD vendors

JetBrains’ public disclosure process for CVE-2026-63077, a private report on July 10, a patch fifteen days later, and a follow-up guidance post in August, tracks reasonably close to industry norms for a vendor-acknowledged critical flaw. GitHub and GitLab, the two largest rivals to TeamCity in the CI/CD market, have both published comparable critical-severity advisories for their own self-hosted products over the past two years, including GitLab’s own critical flaw in its AI Gateway component disclosed in late September 2026 that could let an authenticated user escape a prompt sandbox and execute commands on self-hosted gateways.

What sets this incident apart is not the disclosure timeline, it is the fact that the vendor’s own production environment was reportedly compromised through the flaw after the patch was already available. Neither GitHub nor GitLab has disclosed a comparable self-inflicted breach tied to one of their own unpatched advisories in 2026. That distinction is likely to shape how enterprise security teams weigh TeamCity against GitHub Actions, GitLab CI, Jenkins, and CircleCI during the next round of vendor risk assessments.

Market impact: DevOps security spending gets another data point

Every high-profile CI/CD compromise strengthens the argument that application security budgets need to extend past the code itself and into the tooling that builds and ships it. Security vendors selling software supply chain protection, secrets scanning, and CI/CD runtime monitoring will likely point to CVE-2026-63077 in sales conversations for the rest of 2026, the same way the SolarWinds and Codecov incidents reshaped supply-chain security budgets a few years earlier.

For JetBrains, the commercial exposure is more direct. TeamCity competes with GitHub Actions, GitLab CI, CircleCI, and Jenkins for enterprise CI/CD budget, and a vendor-side breach through its own patched product is the kind of headline that procurement teams raise during renewal conversations. JetBrains has not disclosed financial figures tied to the incident, and no breach-cost estimate has been published for the Cadence intrusion specifically, but the reputational cost of a vendor falling victim to its own flaw tends to linger longer than any single quarter’s revenue line.

What security teams should do right now

The remediation path for CVE-2026-63077 is not complicated, it is a question of whether every instance has actually received it. Teams running TeamCity On-Premises should treat the following as a minimum checklist.

  • Upgrade every TeamCity On-Premises instance to 2025.11.7 or 2026.1.3 or later, not just the primary production server.
  • Inventory every TeamCity deployment across subsidiaries, acquired business units, and shadow-IT instances that central IT may not track.
  • Rotate any cloud credentials, API tokens, and signing keys stored in or accessible from a TeamCity server that was running an unpatched version at any point since July 25, 2026.
  • Review TeamCity server logs for agent polling protocol anomalies dating back to late July, since exploitation may have started before public disclosure.
  • Restrict network access to TeamCity web interfaces to known IP ranges or an internal VPN rather than leaving them reachable from the open internet.
  • Enable multi-factor authentication on any downstream cloud or source-control accounts that a compromised TeamCity server could reach.

None of this is exotic advice. It is the same hardening checklist that applies to any internet-facing build or deployment tool. The difference this time is the messenger: when the vendor itself gets breached through its own patched flaw, “we already fixed it” stops being a reassuring sentence and starts being a reminder that patch deployment, not patch availability, is where most organizations actually fail.

Predictions: where this goes next

Based on how comparable infrastructure-exploitation waves played out in 2024 and 2025, several outcomes look likely over the next two to three months.

  • A named ransomware group or affiliate will be publicly attributed to CVE-2026-63077 exploitation within four to eight weeks, following the same pattern as the Akira-SonicWall attribution timeline in 2025.
  • At least one mid-size or enterprise organization will disclose a confirmed breach tied specifically to an unpatched TeamCity instance, likely surfacing through a public SEC filing or a state breach-notification disclosure given how many public companies run CI/CD on TeamCity.
  • CISA will add further CVEs affecting CI/CD and DevOps tooling, not just VPNs and firewalls, to its KEV catalog before the end of 2026, reflecting the broader shift in ransomware targeting toward build pipelines.
  • JetBrains will publish a more detailed post-incident report on the Cadence breach, similar to the transparency reports SolarWinds and Codecov eventually issued after their own supply-chain incidents.
  • Competing CI/CD vendors, including GitLab and GitHub, will highlight their own security hardening features more aggressively in marketing as enterprise buyers start asking pointed questions about build-server exposure during vendor evaluations.

The bigger picture for software supply chains

CVE-2026-63077 will not be the last critical CI/CD flaw disclosed in 2026, and it is not the first. What makes it worth tracking closely is the compressed timeline between patch, public disclosure, KEV listing, and confirmed ransomware exploitation, and the fact that the vendor’s own infrastructure became a visible casualty. Security teams that treat CI/CD servers with the same urgency they apply to internet-facing VPNs and firewalls will be better positioned for whatever the next version of this story looks like. Those that still think of the build server as an internal, low-risk tool are the ones most likely to provide the next case study. For ongoing coverage of the vulnerabilities, breaches, and ransomware trends shaping 2026, see our cybersecurity threats hub.

Frequently asked questions

What is CVE-2026-63077?
It is a critical, CVSS 9.8-rated deserialization vulnerability in JetBrains TeamCity On-Premises that lets an unauthenticated attacker with network access to the server execute arbitrary operating-system commands through the agent polling protocol.

Which TeamCity versions are affected?
All TeamCity On-Premises versions up to and including 2025.11.6 and 2026.1.2. JetBrains fixed the issue in versions 2025.11.7 and 2026.1.3, released July 25, 2026.

Is TeamCity Cloud affected?
No. JetBrains patches hosted TeamCity Cloud instances centrally, so the exposure applies to self-managed, on-premises deployments.

Has CISA confirmed ransomware exploitation?
Yes. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 5, 2026, and issued a further warning on September 23, 2026 that ransomware gangs were actively exploiting it, without naming a specific group at that time.

Did JetBrains itself get breached through this flaw?
Yes. According to a report published by The Hacker News on September 5, 2026, attackers exploited an unpatched TeamCity instance inside JetBrains’ own Cadence environments to extract AWS credentials.

How is this different from the SonicWall and Akira ransomware attacks of 2025?
Both involve unauthenticated exploitation of critical infrastructure software, but the SonicWall case targeted VPN appliances at the network edge, while CVE-2026-63077 targets a CI/CD server that typically holds cloud credentials and source-code access deeper inside the network.

What should organizations do if they run TeamCity On-Premises?
Upgrade immediately to 2025.11.7 or 2026.1.3 or later, inventory every instance across the organization, rotate any credentials the server could access, and restrict network exposure of the TeamCity web interface.

Who discovered CVE-2026-63077?
JetBrains has stated the issue was privately reported to the company on July 10, 2026. The identity of the reporting researcher or organization has not been publicly disclosed.

Nadia Dubois

AI & Innovation Editor

Nadia Dubois is the AI & Innovation Editor at Tech Insider, where she tracks the rapid evolution of artificial intelligence, from foundation models to real-world enterprise deployment. She previously covered AI and startups for La Tribune and contributed to MIT Technology Review’s European coverage. Nadia specializes in generative AI, AI regulation, and the intersection of technology and European industrial policy. She holds a dual degree in Computational Linguistics and Journalism from Sciences Po Paris.

View all articles

——————————————————–


Click Here For The Original Source.

.........................