CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw
CISA warns federal agencies that ransomware groups are exploiting CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity. Patch released July 28.

Ransomware operators are actively exploiting CVE-2026-63077 in JetBrains TeamCity On-Premises. CISA issued the advisory Wednesday, warning federal agencies.
Exploitation: confirmed. CVE-2026-63077 is on the CISA Known Exploited Vulnerabilities catalog. No specific ransomware groups named in the advisory.
CVSS 9.8 critical. Unauthenticated RCE in all JetBrains TeamCity On-Premises builds before 2025.11.7 and 2026.1.3.
- July 28: JetBrains patches CVE-2026-63077. All on-prem versions in scope.
- July 29: Rapid7 traces the attack path to the TeamCity agent protocol. Exploitation unconfirmed at that stage.
- September 6: JetBrains Cadence breached via an unpatched TeamCity instance. AWS keys and source code stolen.
- September 23: CISA confirms ransomware operators exploiting the flaw in active attacks.
Two months since patch release. Unpatched builds are now confirmed ransomware targets. CISA issued a comparable advisory about WatchGuard Firebox ransomware exploitation two weeks ago.
- [ CRITICAL ]CVE-2026-63077JetBrains TeamCity On-Prem Unauthenticated RCE
Found this useful? Share it.


