{"id":244474,"date":"2026-09-25T01:21:49","date_gmt":"2026-09-25T06:21:49","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw"},"modified":"2026-09-25T01:21:49","modified_gmt":"2026-09-25T06:21:49","slug":"cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw","title":{"rendered":"CISA: Ransomware gangs now exploiting critical TeamCity flaw"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw.jpg\"><\/a><\/p>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.<\/p>\n<p>JetBrains patched the security flaw (tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-63077\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026\u201363077<\/a>) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw\/\" target=\"_blank\" rel=\"nofollow noopener\">critical authentication bypass vulnerability<\/a> that lets attackers with HTTP(S) access execute arbitrary operating system commands.<\/p>\n<p>\u201cAn unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,\u201d it said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. JetBrains patched the security flaw (tracked as CVE-2026\u201363077) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a critical authentication bypass vulnerability that [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-244474","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244474"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244474\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}