CISA says ransomware groups now exploit JetBrains TeamCity flaw CVE-2026-63077
CISA updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-63077, a critical TeamCity authentication bypass patched by JetBrains on July 25, as now being abused in ransomware attacks. JetBrains had already confirmed in-the-wild exploitation on August 7, and CISA had ordered federal agencies on August 5 to secure their systems within three days. Shadowserver currently tracks roughly 160 unpatched TeamCity servers still exposed to the flaw.