What Happened
CVE-2026-63077 is an authentication bypass in TeamCity On-Premises, the self-hosted build and continuous-integration server from JetBrains. The flaw lets an unauthenticated attacker send crafted requests through the agent polling protocol and run operating system commands with the privileges of the TeamCity server process. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal patch deadline.
CISA has now updated this catalog entry to flag exploitation by ransomware operators, though the advisory does not name a specific group. The update signals a shift from opportunistic probing to deliberate use by criminal groups seeking a foothold in build environments. Read the update from BleepingComputer.
Why This Matters for Canadian Organizations
TeamCity sits deep inside a software development pipeline, orchestrating builds, tests, and deployments for products a company ships to its own customers. A ransomware operator reaching a TeamCity server gains far more than one machine to encrypt. Attackers gain access to source code, build secrets, and signing credentials used across every downstream product the server builds, turning a single compromise into a supply-chain incident affecting a company’s customers as well as its own network.
Canadian software vendors, fintechs, and enterprise development teams running self-hosted TeamCity carry this risk directly. A ransomware group operating inside a build server threatens both operational continuity under OSFI B-13 resilience expectations and any personal or financial data touched by affected applications, raising PIPEDA notification duties if this data gets exposed alongside the encryption event.
What to Do
Check the TeamCity On-Premises version running in your environment now and apply the vendor patch without delay. Where patching needs coordination across teams, restrict network access to the agent polling endpoint in the meantime, limiting it to known build agents only. Review server logs back to early August for signs of the exploitation pattern CISA describes, and rotate build secrets, API keys, and signing credentials stored in TeamCity if any sign of compromise turns up.
Track related vulnerability coverage in our TechTalk section and daily updates in News.






