CISA: ransomware gangs now exploiting critical TeamCity flaw
CISA warned U.S. federal agencies that ransomware gangs are now exploiting a critical JetBrains TeamCity vulnerability, CVE-2026-63077. The authentication bypass in TeamCity On-Premises was patched on July 25 in versions 2025.11.7 and 2026.1.3 and is already in CISA's KEV catalog.
- CVE-2026-63077 is an auth bypass allowing OS command execution
- Patched July 25 in TeamCity On-Premises 2025.11.7 and 2026.1.3
- CISA added it to KEV on August 5 with a three-day patch deadline
- Shadowserver tracks about 160 unpatched TeamCity servers
Read next
Security