mimile
Back to feed

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

The Australian Cyber Security Centre (ACSC) warned that threat actors are actively exploiting a critical vulnerability in TeamCity On-Premises servers. The flaw, CVE 2026-63077, allows unauthenticated attackers to bypass authentication and execute arbitrary OS commands. All Australian organizations using TeamCity On-Premises are at risk, and the ACSC urged urgent patching.

Key Facts

  • CVE 2026-63077 has a critical CVSS score of 9.8 and affects all TeamCity On-Premises versions.
  • JetBrains first disclosed the vulnerability and issued patches in July 2026.
  • CISA added CVE 2026-63077 to its Known Exploited Vulnerabilities Catalog on August 5, 2026.
  • JetBrains issued a follow-up advisory on August 7, 2026, after receiving reports of active and attempted exploitation.
  • JetBrains advised customers to update to TeamCity 2025.11.7 or 2026.1.3, or install the security patch plugin.

Vulnerability Details

CVE 2026-63077 allows unauthenticated attackers with HTTP(S) access to bypass authentication checks and execute arbitrary operating system commands. The flaw affects all TeamCity On-Premises versions and carries a critical CVSS score of 9.8. JetBrains, the owner of TeamCity, first disclosed the vulnerability in July 2026 when patches were issued. TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server used by thousands of organizations worldwide.

Active Exploitation and Response

The Australian Cyber Security Centre (ACSC) warned that threat actors are actively exploiting CVE 2026-63077 to access TeamCity On-Premises servers. The ACSC said it has no evidence that a specific industry or sector is being targeted, but all Australian organizations using TeamCity On-Premises are at risk. The agency urged TeamCity customers to urgently review networks for vulnerable versions and apply patches if necessary. The ACSC also advised organizations to consider whether they need to have their TeamCity interface exposed to the internet. CISA added CVE 2026-63077 to its Known Exploited Vulnerabilities Catalog on August 5, 2026, citing evidence of active exploitation.

Historical Context

In 2024, two vulnerabilities affecting TeamCity On-Premises software were extensively exploited by attackers, with the most severe allowing complete compromise by a remote unauthenticated attacker. Another critical vulnerability disclosed in 2023 was targeted by Russian and North Korean nation-state actors. JetBrains issued a follow-up advisory on August 7, 2026, after receiving reports of active and attempted exploitation targeting unpatched TeamCity servers. The company said customers who have not updated to TeamCity 2025.11.7 or 2026.1.3, or installed the security patch plugin, should do so immediately.

1 source

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw