Mathew Potter
Security Analyst
CISA already had CVE-2026-63077 on the exploited list in August. Wednesday they added the ransomware tag. JetBrains patched it July 25. Unauthenticated, HTTP to the TeamCity server, commands as the TeamCity process. Build configs, stored credentials, and the artifacts you ship are in that blast. Shadowserver still sees about 160 internet-facing boxes that have not moved, down from about 700 right after the patch. The federal clock was August 8. If you are still on last spring's build, you are late twice.
TeamCity On-Premises before 2025.11.7 and 2026.1.3. The hole is in the agent polling path. We are not going to walk it. JetBrains said anyone who can reach the web interface can bypass the login check and run commands with whatever rights the server process has. Cloud is out of scope. A security-patch plugin exists for older 2017.1 and later trains if you cannot jump versions today. That plugin is this CVE only. The full build is the real close.
JetBrains confirmed use on August 7 and published hunt notes. CISA has now said ransomware crews are in that use. They have not named a group or a victim list. Since late 2023 they have tagged four TeamCity holes as exploited, and all four have shown up in ransomware campaigns. APT29 went after TeamCity and Zimbra at scale in the 2024 advisory. This is not a new product class. It is a build server that still has a public IP.
A surprising number of Alberta product firms, MSPs, and even internal IT teams run TeamCity because a developer stood it up five years ago. The box builds the customer portal, the mobile app, or the script that pushes to the shop PCs. If that box is on the internet and unpatched, ransomware is not a file-share story. It is a signed-looking build story. The copies you trust may have been built on a box someone else already owns.
A build server that ransomware crews can reach without a password is not a developer toy. Forensic Five reviews the box that produces the software you ship, not only the website it deploys. From St. Albert, Alberta. Move the version. Then go finish the switch before the day is over.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.