CISA said Sept. 23 that ransomware crews are exploiting CVE-2026-63077, an unauthenticated 9.8 RCE in JetBrains TeamCity patched July 25. Any build server patched late has to be handled as breached, including the credentials and signing keys it held.
Reality
- Evidence70
- Adoption75
- Hype gap+15
- Incentives35
- Confidence72
The September 3 note closed the investigation without adding a single affected user, but it put project source code and credentials in current Cadence storage inside a blast radius that had been limited to a 2024 backup.
Reality
- Evidence64
- Adoption42
- Hype gap−22
- Incentives78
- Confidence61
CVE-2026-63077 was in CISA's KEV catalog on August 5. JetBrains dates the intrusion into its own Cadence environment from August 8 to August 24, and every secret that touched the service now needs rotating.
Reality
- Evidence62
- Adoption38
- Hype gap−8
- Incentives66
- Confidence64
The reductions run deepest on the largest machines. That redoes the arithmetic that sent heavy jobs to hardware you own. The per-minute charge GitHub proposed for self-hosted runners still has no new date.
Reality
- Evidence58
- Adoption52
- Hype gap+10
- Incentives72
- Confidence57
Build configurations can now authenticate to AWS and Google Cloud without stored keys, provided you accept that the TeamCity server holds the signing key and that rotating it leaves already-issued tokens valid.
Reality
- Evidence46
- Adoption12
- Hype gap+14
- Incentives82
- Confidence56
JetBrains says CVE-2026-63077 lets an unauthenticated attacker run arbitrary commands on a TeamCity server. The rotation list it handed Cadence users doubles as the recovery scope for anyone self-hosting.
Reality
- Evidence79
- Adoption71
- Hype gap−9
- Incentives73
- Confidence74
Wiz says a TeamCity honeypot exposing JDWP was mining Monero within hours, and GreyNoise counted more than 6,000 unique IPs scanning for the protocol in 90 days.
Reality
- Evidence63
- Adoption52
- Hype gap+12
- Incentives70
- Confidence58