CISA confirmed that ransomware campaigns are exploiting CVE-2026-63077, a CVSS 9.8 unauthenticated remote-code-execution flaw in JetBrains TeamCity. The deserialization vulnerability affects the agent polling protocol and can allow remote attackers to execute code without authentication; CISA updated its Known Exploited Vulnerabilities catalog to mark ransomware use as known.
JetBrains released a fix on July 25, and CISA added the flaw to the KEV catalog in August with an August 8 remediation deadline under BOD 26-04. Organizations should urgently apply vendor mitigations to exposed TeamCity servers, rotate build, signing, cloud, and access credentials that may have been exposed, and investigate build logs, pipeline configurations, and artifacts for unauthorized changes or downstream compromise.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA updated CVE-2026-63077's KEV entry to change its ransomware-campaign-use status from Unknown to Known, confirming exploitation in ransomware campaigns.
CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog and directed organizations to apply vendor mitigations. The catalog set an August 8 remediation due date and marked the issue as requiring forensic triage.
JetBrains released a patch for CVE-2026-63077, a CVSS 9.8 unauthenticated remote-code-execution flaw in TeamCity's agent polling protocol.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.