logo

JetBrains TeamCity Auth Bypass Vulnerability Exploited

ID: 89e69791-0cd5-50ea-b12c-ef527882f6fa

STIX ID: report--89e69791-0cd5-50ea-b12c-ef527882f6fa

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

On March 4, 2024 JetBrains released patches for two authentication-bypass vulnerabilities in TeamCity (CVE-2024-27198 — critical, and CVE-2024-27199 — high); Rapid7 published details and public exploits soon after, and Cyble observed active exploitation of CVE-2024-27198 from March 5, 2024 onward. The report notes 1,780 internet-exposed TeamCity instances, captured exploitation attempts in sensor data, a set of IoCs (multiple attacker IPs), and underground forum activity selling compromised TeamCity access; it recommends immediate patching, network segmentation, monitoring of TeamCity logs, and regular assessments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.