Summary
CISA has issued an advisory confirming that multiple ransomware groups are actively exploiting CVE-2026-37151, a critical authentication bypass vulnerability in JetBrains TeamCity CI/CD server that allows unauthenticated remote attackers to create administrator accounts and take full control of the build server. The vulnerability is rated CVSS 9.8 and affects all on-premises TeamCity instances running versions prior to the patched release. Ransomware operators have moved quickly from exploitation to deployment, using compromised TeamCity servers as a foothold for lateral movement into development and production environments. CISA has added CVE-2026-37151 to its Known Exploited Vulnerabilities catalog with a September 26 deadline for federal agencies to patch or disconnect affected instances.
Timeline
| Date | Event |
|---|---|
| Prior to Sep 23, 2026 | CVE-2026-37151 exploited by multiple threat actors; JetBrains patches and discloses vulnerability |
| Sep 23, 2026 | CISA confirms ransomware gang exploitation; adds CVE-2026-37151 to KEV catalog with September 26 federal deadline |
| Sep 24, 2026 | BleepingComputer reports full campaign details; TTO-2026-0924-160 published |
What Happened
CVE-2026-37151 is an authentication bypass in TeamCity’s REST API endpoint used for initial setup and administrative access. The endpoint fails to enforce authentication checks under certain conditions, allowing an unauthenticated attacker to submit requests that create a new administrator account with a known password. Once an administrator account exists, the attacker has full access to the TeamCity server: build configurations, source code repositories, build artifacts, environment variables, stored credentials, and deployment pipelines.
TeamCity’s privileged position in software development pipelines makes it a high-value target. Build servers routinely hold credentials for source code repositories, cloud environments, artifact registries, and production deployment targets. An attacker who compromises TeamCity can inject malicious code into build pipelines, steal credentials for every connected system, and pivot directly into production environments through legitimate deployment channels. CISA’s advisory documents ransomware operators using this exact path: TeamCity compromise to credential theft to lateral movement to ransomware deployment. Organizations running on-premises TeamCity should patch immediately, rotate all credentials stored in or accessible from the TeamCity server, and audit build pipeline logs for unauthorized modifications.
Domain Intelligence
jetbrains.com — 62.52
jetbrains.com scores in the low-trust range at 62.52. JetBrains is the vendor of the affected TeamCity CI/CD product and the party that patched CVE-2026-37151. One threat intelligence source has flagged jetbrains.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 24, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026