Executive Summary
In July 2026, JetBrains patched a critical authentication bypass vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary operating system commands via the agent polling protocol. CISA added the flaw to its Known Exploited Vulnerabilities catalog in August after confirming active exploitation, ordering federal agencies to patch within three days. The vulnerability exposes TeamCity data, configurations, stored credentials, and can compromise CI/CD pipeline integrity, affecting over 30,000 DevOps teams at major companies including Citibank, Amazon Games, Tesla, and Samsung.
This incident highlights the accelerating trend of ransomware groups rapidly weaponizing CI/CD infrastructure vulnerabilities, marking the fourth TeamCity flaw exploited in ransomware campaigns since October 2023, as attackers increasingly target development pipelines to maximize operational disruption and data access.
Why This Matters Now
Ransomware groups are systematically targeting CI/CD infrastructure like TeamCity to gain privileged access to source code, build artifacts, and deployment pipelines, creating unprecedented supply chain risks that can cascade across entire software ecosystems and require immediate defensive prioritization.
Attack Path Analysis
Ransomware gangs exploited CVE-2026-63077, a critical authentication bypass vulnerability in Internet-exposed JetBrains TeamCity servers to gain initial access and execute arbitrary OS commands. Attackers leveraged TeamCity server process privileges to access stored credentials and configurations, then moved laterally through CI/CD pipelines to compromise build artifacts and connected systems. Command and control was established through compromised infrastructure while attackers exfiltrated sensitive data including source code, credentials, and build configurations. Finally, ransomware was deployed across the environment, encrypting critical systems and demanding payment for decryption keys.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-63077 authentication bypass vulnerability in Internet-exposed TeamCity servers via the agent polling protocol to execute arbitrary OS commands without authentication
Related CVEs
CVE-2026-63077
CVSS 9.8Critical authentication bypass vulnerability in JetBrains TeamCity that allows unauthenticated attackers to execute arbitrary operating system commands via the TeamCity agent polling protocol.
Affected Products:
JetBrains TeamCity On-Premises – < 2025.11.7, < 2026.1.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Command and Scripting Interpreter: Unix Shell
Valid Accounts
Server Software Component: Web Shell
Data Encrypted for Impact
Inhibit System Recovery
Remote System Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software security patches and updates
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Vulnerability Management
Control ID: 500.02(h)
CISA ZTMM 2.0 – Secure Software Development and Deployment
Control ID: Application Security
DORA – Management of ICT risk
Control ID: Article 9
NIS2 Directive – Cybersecurity measures
Control ID: Article 21
ISO 27001:2022 – Management of technical vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical TeamCity vulnerability enables ransomware gangs to bypass authentication and compromise CI/CD pipelines, exposing source code and development infrastructure.
Information Technology/IT
TeamCity exploitation allows unauthorized system access and lateral movement, threatening IT infrastructure integrity and requiring immediate patch management across environments.
Financial Services
Authentication bypass vulnerability compromises build artifacts and CI/CD security, risking financial application integrity and regulatory compliance violations including PCI standards.
Government Administration
CISA-flagged TeamCity ransomware exploitation threatens federal agency operations, requiring emergency patching within three days per cybersecurity directives.
Sources
- CISA: Ransomware gangs now exploiting critical TeamCity flawhttps://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/Verified
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalogVerified
- JetBrains TeamCity CVE-2026-63077 Security Updatehttps://blog.jetbrains.com/teamcity/2026/08/cve-2026-63077-update/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the lateral movement and blast radius of this TeamCity ransomware attack by implementing workload segmentation and controlled access paths. The fabric's east-west enforcement and egress controls could reduce the scope of CI/CD pipeline compromise and data exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The fabric's visibility and monitoring capabilities would likely detect the exploitation attempt and unauthorized command execution on the TeamCity infrastructure, potentially alerting security teams to the initial compromise activity.
Control: Zero Trust Segmentation
Mitigation: Workload-level segmentation would likely constrain the attacker's ability to access credential stores and configuration databases, reducing the scope of sensitive data exposure within the CI/CD environment.
Control: East-West Traffic Security
Mitigation: East-west enforcement policies would likely restrict lateral movement paths between CI/CD systems and connected development environments, constraining the attacker's ability to compromise additional build infrastructure and downstream systems.
Control: Multicloud Visibility & Control
Mitigation: Comprehensive visibility across cloud environments would likely detect unauthorized communication patterns and suspicious traffic flows from the compromised TeamCity infrastructure, potentially identifying command and control activities.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely restrict unauthorized data transfers from the CI/CD environment, constraining the attacker's ability to exfiltrate source code, credentials, and build configurations to external destinations.
While ransomware deployment may still occur on initially compromised systems, the reduced lateral movement and constrained access paths would likely limit the encryption scope to fewer critical systems and environments.
Impact at a Glance
Affected Business Functions
- Software Development and CI/CD Pipelines
- Source Code Management
- Build and Deployment Automation
- DevOps Operations
Estimated downtime: 7 days
Estimated loss: $250,000
TeamCity server configurations, stored credentials, build artifacts, source code repositories, and CI/CD pipeline integrity potentially compromised affecting software development operations
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate CI/CD infrastructure from broader network environments and limit lateral movement potential
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts and command & control communications
- • Enable Multicloud Visibility & Control to monitor anomalous CI/CD activities and detect suspicious automation patterns across development environments
- • Implement Inline IPS (Suricata) to identify and block known exploit patterns targeting TeamCity vulnerabilities at the network perimeter
- • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous threat detection to prevent initial compromise of critical development infrastructure



