New! Try the FREE Predictive Security Plugin for WordPress – Scan, Secure & Stay Safe in Seconds!

Current CyberSecurity Advisories

Active exploitation of a software development platform within Australia

Release date
24 August 2026
Alert rating
High

Description

Alert on actively exploited vulnerabilities affecting TeamCity On-Premise servers. Assess exposure and apply vendor mitigations for CVE 2026 63077 (Critical, 9.8).

Audience

Small & medium businessesOrganisations & Critical InfrastructureGovernment

Current update

This alert is relevant to all Australian organisations that utilise the TeamCity On-Premises server. This alert is intended for a technical audience.

Background

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia.

  • TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software.

CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.

This vulnerability affects all TeamCity On-Premises versions.

ASD’s ACSC has no information to indicate that a specific industry or sector is being targeted.

Mitigation advice 

ASD’s ACSC advises organisations to ensure the following:

  • Review networks and environments for use of vulnerable versions of the TeamCity On-Premises server.
  • Review the need to continue to have the interface exposed to the internet.
  • Review the mitigation advice on the vendor support page
  • If TeamCity Server is managed by a third party, such as a MSP or Enterprise IT provider, you should contact that provider to ensure the products have been patched and are being monitored for suspicious activity.
  • Apply patches as soon as practicable, if required.
  • Monitor for suspicious activity. Indicators of Compromise (IoC) have been released by the vendor, which may assist in detecting malicious activity. 
  • If suspicious activity is detected, notify ASD’s ACSC.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).

Protect your assets with Predictive