"An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains wrote after patching the flaw.
CVE-2026-63077: what was patched and why it matters
JetBrains released fixes for CVE-2026-63077 on July 25, updating TeamCity On‑Premises to versions 2025.11.7 and 2026.1.3. The company described the bug as a "critical authentication bypass vulnerability" that allows an attacker with HTTP(S) access to run arbitrary operating system commands. JetBrains warned that, "Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines."
CISA's timeline: patch, cataloging, and agency orders
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) moved quickly after the July patch. On August 5 CISA added CVE-2026-63077 to its catalog of actively exploited vulnerabilities and ordered U.S. federal agencies to secure their networks against ongoing attacks within three days. CISA also warned federal agencies on a Wednesday that ransomware gangs are now exploiting the TeamCity vulnerability and later updated its Known Exploited Vulnerabilities (KEV) Catalog to flag the flaw as being abused by ransomware groups.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildExploitation in the wild and defensive signals from JetBrains
JetBrains confirmed the vulnerability was exploited in the wild on August 7, and the vendor shared indicators of compromise while advising customers who could not immediately patch to limit access to trusted networks. CISA, however, "has not yet shared any information regarding attacks targeting CVE-2026-63077," according to the reporting. The appearance of active exploitation prompted CISA to reclassify the flaw on its KEV list and to direct federal agencies to take rapid mitigations.
Shadowserver counts and the continuing exposure of TeamCity servers
Independent tracker Shadowserver reported that roughly 700 Internet‑exposed TeamCity servers were initially vulnerable; that number has since fallen to just over 160 unpatched servers being tracked. The decline indicates some patching and mitigation activity, but the remaining exposed instances represent a continuing risk. CISA and JetBrains both signaled urgency: CISA by its cataloging and agency order, JetBrains by publishing IOCs and recommending network access limits for unpatched systems.
What this means for DevOps teams, U.S. federal agencies, and enterprises
- DevOps teams and security engineers: TeamCity is a CI/CD platform used to automate building, testing, and deploying code; JetBrains says more than 30,000 DevOps teams use TeamCity at organizations including Citibank, Amazon Games, Tesla, and Samsung. Those teams face immediate choices — apply the July 25 updates to 2025.11.7 or 2026.1.3, or, until they can, restrict TeamCity server access to trusted networks and consume the indicators of compromise JetBrains published.
- U.S. federal agencies: CISA ordered agencies to secure their networks within three days after adding the CVE to its actively exploited catalog on August 5, underscoring the expectation of rapid, centrally coordinated mitigation for KEV-listed flaws.
- Large enterprises and CISOs: With CISA flagging ransomware gangs as active abusers of the flaw, organizations that run Internet‑exposed TeamCity servers must weigh the operational risk to build artifacts, stored credentials, and downstream CI/CD pipelines — potential impacts JetBrains explicitly listed.
Attack patterns around TeamCity are not entirely new. The reporting cites an October 2024 warning from U.S. and U.K. cyber agencies that APT29 hackers linked to Russia's Foreign Intelligence Service (SVR) were targeting vulnerable JetBrains TeamCity and Zimbra servers "at a mass scale," a reminder that both state‑backed groups and criminal ransomware operators have previously leveraged TeamCity weaknesses.
The immediate facts are straightforward: a critical authentication bypass in widely used CI/CD software was patched on July 25, tracked as CVE-2026-63077; CISA moved the flaw into its KEV list on August 5 and issued a short remediation deadline for federal agencies; JetBrains confirmed exploitation on August 7 and published IOCs while recommending access restrictions for unpatched servers; and security monitors still find more than 160 Internet‑exposed TeamCity instances unpatched.
The remaining questions are operational. Will the last exposed TeamCity servers be patched quickly enough to prevent more ransomware-related compromises? CISA has signaled the vulnerability is too severe to leave unaddressed; JetBrains has supplied fixes and indicators; and Shadowserver's tracking shows the scale of the remaining exposure. For defenders, the choice is concrete and immediate: apply the published TeamCity updates or enforce restrictive network controls until they can.




