ZeroHour

CVE-2024-27199

KEV ransomware PoC large1

Path Traversal in JetBrains TeamCity Allows Limited Admin Actions

CISA: JetBrains TeamCity Relative Path Traversal Vulnerability

CVSS 3.1
7.3 high
EPSS
100%p100
Published
()
KEV added
AI analysis

JetBrains TeamCity, a widely used continuous integration/continuous delivery (CI/CD) server, contains a relative path traversal vulnerability (CWE-23) in which the application fails to properly neutralize traversal sequences in file paths. An attacker who can reach the vulnerable component can supply crafted relative paths that escape the intended directory, gaining the ability to perform limited administrative actions on the TeamCity server. Any organization running an affected JetBrains TeamCity deployment, especially instances exposed to the internet or reachable by untrusted users, is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20 with known ransomware use, and the EPSS model assigns it a 100% probability of exploitation within the next 30 days. No public proof-of-concept is known, but the KEV listing confirms active exploitation in the wild per CISA.

What to do: Upgrade TeamCity to the patched release identified in JetBrains' security bulletin, or if patching is not immediately possible, apply vendor-recommended mitigations and restrict internet access to the server; federal agencies must follow BOD 22-01 guidance, including for cloud service offerings, or discontinue use if mitigations are unavailable. Given the known ransomware association, review TeamCity logs, admin accounts, and build-agent activity for signs of tampering as part of remediation.

Affected
JetBrains TeamCityAffected as listed by CISA; the source data provides no specific affected version ranges, so verify exact affected and patched versions in JetBrains' security b
Estimated exposure
large~10,000-30,000 TeamCity server deployments, with a meaningful share of those exposed directly to the internet (order of magnitude 10^4) — TeamCity is enterprise CI/CD software rather than consumer software, and public internet-wide scans have historically shown on the order of tens of thousands of TeamCity instances reachable from the internet, with additional intranet-only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CISA Known Exploited Vulnerability
Affected
JetBrains TeamCity
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
jetbrains
Products
teamcity
Weakness
CWE-23, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.

Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.

Security Affairs · Aug 13, 2026Ransomware in the wildCVE-2026-18577CVE-2026-1731CVE-2023-21529+15 CVEs