Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

TeamCity CVE-2026-63077 ransomware ransomware vulnerability featured image

Ransomware Is Still Hitting TeamCity: CVSS 9.8 Flaw Puts Build Pipelines at Risk

If your organisation runs JetBrains TeamCity On-Premises and hasn't patched since July, ransomware gangs have likely already tried to walk in through CVE-2026-63077, a critical unauthenticated RCE flaw that CISA confirmed as actively exploited two months ago.

The vulnerability, rated CVSS 9.8, sits in the agent polling endpoint and exploits improper deserialisation of untrusted data. No authentication required, no user interaction needed. An attacker sends a crafted HTTP request to your TeamCity server and gets full remote code execution as the TeamCity service account. Tech Insider reported this week that ransomware groups have continued targeting unpatched instances, with JetBrains' own infrastructure breached in September after credentials from an earlier attack were reused.

Why This Is Worse Than a Typical Server Compromise

TeamCity isn't just another server. It sits at the centre of your software delivery pipeline, holding build secrets, cloud API keys, deployment credentials, and source code access. Compromise it and the attacker owns everything downstream. For Australian businesses using TeamCity to automate deployments into cloud environments or client infrastructure, that means one unpatched server can cascade into a full supply chain incident.

Managed service providers running shared TeamCity instances face the sharpest exposure: one breached server can hand attackers access to build jobs and credentials spanning every client environment connected through it. This is not theoretical. CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalogue in August, with an eight-day remediation deadline for federal agencies. That clock applies to the private sector too, in practice.

Patch deadline passed: CISA's KEV remediation deadline for CVE-2026-63077 was August 8, 2026. If you haven't patched, exploitation risk has been accumulating for two months. Treat this as urgent.

What to Do Right Now

  • Upgrade immediately. Patch to TeamCity 2025.11.7 or 2026.1.3. JetBrains also released a security patch plugin for users on version 2017.1 or later who can't do a full upgrade right now.
  • Rotate every secret the server touched. API keys, cloud credentials, deployment tokens: all of them. If the server ran unpatched while exploitation was active, treat those secrets as compromised.
  • Restrict network access. TeamCity should not be internet-facing. Put it behind a VPN or firewall and enforce MFA on all console access.
  • Audit build logs and agent connections. Look for unfamiliar agents, unexpected script executions, or new user accounts, especially any with a .invalid email suffix, which is a known indicator from previous RMM-targeting campaigns.

TeamCity Cloud users require no action. This flaw affects self-hosted On-Premises installations only. If you're unsure which version your organisation runs, that's your first task.

How All IT Handles Vulnerability Management for Clients

All IT monitors CISA's Known Exploited Vulnerabilities catalogue and vendor security advisories as part of ongoing managed services for clients in Sydney, the Northern Beaches, Central West NSW, and beyond. When a critical CVE like this surfaces, we assess client exposure, push patching where it applies, and confirm remediation, rather than waiting for a quarterly review cycle. If your current IT setup doesn't include proactive patch tracking, that's a gap worth closing before the next CVSS 9.8 lands.

All IT Cybersecurity Services: vulnerability monitoring, patch management, and incident response for Australian businesses that need to stay ahead of the next advisory.

Frequently Asked Questions

What is CVE-2026-63077 in JetBrains TeamCity?

CVE-2026-63077 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises. It exploits improper deserialisation in the agent polling endpoint, allowing an attacker with no credentials or user interaction to run arbitrary commands on the TeamCity server. It affects all On-Premises versions before 2025.11.7 and 2026.1.3, and has been actively exploited since August 2026.

Am I affected if I use TeamCity Cloud?

No. TeamCity Cloud (JetBrains-hosted) is not affected by CVE-2026-63077 and requires no action. Only self-hosted, on-premises TeamCity installations are at risk. If you are unsure which version your organisation runs, check with your IT team or managed service provider.

What can attackers do if they exploit this flaw?

A successful exploit gives the attacker full remote code execution as the TeamCity service account. From there they can access source code repositories, extract build secrets, steal API keys and deployment credentials, and push malicious code into build pipelines. For managed service providers, a single compromised TeamCity server can expose downstream client environments, making this a supply chain risk, not just a server compromise.

How do I patch TeamCity against CVE-2026-63077?

Upgrade TeamCity On-Premises to version 2025.11.7 or 2026.1.3 immediately. JetBrains also released a security patch plugin for version 2017.1 and later if an in-place upgrade is not immediately possible. After patching, rotate any cloud credentials, API keys, and secrets that the TeamCity server had access to, because they must be treated as compromised if the server ran unpatched while exploitation was active.

Not Sure If Your Environment Is Patched?

All IT can assess your exposure to CVE-2026-63077 and other active threats, and get patching sorted before the next incident. Month-to-month, no lock-in.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →