CISA put a ransomware tag on the July TeamCity hole. About 160 boxes are still out there.
Vulnerability Management

CISA put a ransomware tag on the July TeamCity hole. About 160 boxes are still out there.

Mathew Potter

Security Analyst

September 24, 2026

CISA already had CVE-2026-63077 on the exploited list in August. Wednesday they added the ransomware tag. JetBrains patched it July 25. Unauthenticated, HTTP to the TeamCity server, commands as the TeamCity process. Build configs, stored credentials, and the artifacts you ship are in that blast. Shadowserver still sees about 160 internet-facing boxes that have not moved, down from about 700 right after the patch. The federal clock was August 8. If you are still on last spring's build, you are late twice.

What the July patch actually closed

TeamCity On-Premises before 2025.11.7 and 2026.1.3. The hole is in the agent polling path. We are not going to walk it. JetBrains said anyone who can reach the web interface can bypass the login check and run commands with whatever rights the server process has. Cloud is out of scope. A security-patch plugin exists for older 2017.1 and later trains if you cannot jump versions today. That plugin is this CVE only. The full build is the real close.

JetBrains confirmed use on August 7 and published hunt notes. CISA has now said ransomware crews are in that use. They have not named a group or a victim list. Since late 2023 they have tagged four TeamCity holes as exploited, and all four have shown up in ransomware campaigns. APT29 went after TeamCity and Zimbra at scale in the 2024 advisory. This is not a new product class. It is a build server that still has a public IP.

Why a shop that "does not do DevOps" still cares

A surprising number of Alberta product firms, MSPs, and even internal IT teams run TeamCity because a developer stood it up five years ago. The box builds the customer portal, the mobile app, or the script that pushes to the shop PCs. If that box is on the internet and unpatched, ransomware is not a file-share story. It is a signed-looking build story. The copies you trust may have been built on a box someone else already owns.

What we would check today

  • Name every TeamCity On-Premises. Write the version. 2025.11.7 or 2026.1.3, or newer. Cloud customers can stop. Everyone else cannot.
  • If it answers on the internet, pull it back to a VPN or a named allow-list today, then patch. July's advice is still today's advice.
  • If you were exposed after July 25, read JetBrains' August hunt note and treat stored credentials as spilled until you rotate them. A clean version number is not a clean history.
  • Zyxel GS1900 firmware is due today. F5 APM hotfix is due tomorrow. WordPress 7.1.2 and Roundcube 1.6.16 / 1.7.1 are this morning's other two.

Bottom line

A build server that ransomware crews can reach without a password is not a developer toy. Forensic Five reviews the box that produces the software you ship, not only the website it deploys. From St. Albert, Alberta. Move the version. Then go finish the switch before the day is over.

Tags

TeamCity CVE-2026-63077 ransomware CISA KEV CI/CD

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.