Critical TeamCity flaw now widely exploited to create admin accounts
ID: f77aa9bf-f2a4-5618-b774-0f90fafb4669
STIX ID: report--f77aa9bf-f2a4-5618-b774-0f90fafb4669
Feed Name: Bleeping Computer
Threat Score
A critical authentication-bypass vulnerability (CVE-2024-27198) in on‑premises JetBrains TeamCity (fixed in 2023.11.4) is being actively exploited in the wild; LeakIX and GreyNoise report thousands of vulnerable servers and over 1,440 confirmed compromises with hundreds of attacker-created admin accounts on exposed instances, creating a significant supply‑chain risk—administrators are urged to apply the patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
