TeamCity CVE-2026-63077 ransomware exploitation

JetBrains TeamCity product logo
TeamCity and its logo are registered trademarks of JetBrains s.r.o.; used for identification.

TeamCity CVE-2026-63077 ransomware exploitation is the central phrase for this report because it captures the specific development readers need to evaluate. An unauthenticated 9.8-rated flaw gives attackers a route into source code, signing credentials and deployment pipelines; fixes have been available since July.

What CISA confirmed

CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on September 23 and said ransomware operations are exploiting it. The 9.8-rated TeamCity On-Premises flaw allows unauthenticated remote code execution: an attacker does not need a valid account before attempting to run code on the build server.

Why a build server is different

A compromised laptop exposes one user; a compromised continuous-integration server can expose source repositories, signing credentials, secrets and deployment pipelines. Attackers can encrypt the server for immediate leverage, steal proprietary code, or alter a trusted build so malicious software travels downstream under the victim’s own release process. That makes the vulnerability a software-supply-chain risk, not only an uptime problem.

The patch-latency story

JetBrains released fixes July 25 in TeamCity On-Premises 2025.11.7 and 2026.1.3. The CISA listing arrived roughly two months later, when reporting cited about 160 internet-reachable, unpatched systems. The important chronology is therefore not an undisclosed zero-day suddenly appearing; it is a known critical flaw remaining exploitable long after remediation was available.

Who wins and who loses

Incident-response firms and security vendors gain urgent work, while operators of patched or isolated systems benefit from disciplined maintenance. Organizations still exposing old on-premises versions face the largest risk, and their customers inherit uncertainty if software produced during a suspected compromise cannot be trusted. JetBrains’ cloud-hosted service was reported unaffected, highlighting the security trade-off between control and operational burden.

What defenders should establish

Operators need more than a version check. They should determine whether the server was reachable, review authentication and process activity, rotate credentials available to the build system, validate artifacts and preserve evidence before rebuilding. The forward question is whether investigators find only opportunistic encryption or evidence that attackers used TeamCity as a bridge into signed releases. CISA’s catalog entry makes delay indefensible.

Related Signal Post News coverage

CISA’s separate Check Point deadline the push toward locally controlled security AI

Sources and reporting basis

Reporting note: This is a fixed September 25, 2026 snapshot. Attributed claims remain attributed; forecasts, polls, vendor results and early cyber findings can change as new evidence appears.

Technology / Cybersecurity · Published September 25, 2026Back to latest reports