CISA: Ransomware gangs now exploiting critical TeamCity flaw
AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs are actively exploiting a critical authentication bypass vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077. This flaw allows unauthenticated attackers to execute arbitrary operating system commands via the TeamCity agent polling protocol, potentially compromising CI/CD pipelines, stealing credentials, and modifying server state. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate within three days. Although patching is available, hundreds of internet-exposed TeamCity servers remain unpatched, making them attractive targets for ransomware and state-sponsored actors.
AI-extracted · verify before operational use