# Australian Cybersecurity Center Urges Immediate Action on TeamCity Vulnerability

*Published August 26, 2026*
*Source: [https://www.infosecurity-magazine.com/news/australia-exploitation-teamcity/](https://www.infosecurity-magazine.com/news/australia-exploitation-teamcity/)*

## Executive Summary

Australian authorities have alerted organizations about an actively exploited critical vulnerability in TeamCity On-Premises servers. Immediate patching is recommended to prevent unauthorized access and potential system compromise.

## Article

The Australian Cyber Security Centre has issued an urgent warning regarding the active exploitation of a critical vulnerability in TeamCity On-Premises servers. The flaw, identified as CVE 2026-63077, allows unauthorized attackers to bypass authentication and execute arbitrary commands on the operating system. This vulnerability affects all versions of TeamCity On-Premises and poses a significant risk to organizations using the service. Although no specific industry has been targeted, all Australian organizations with TeamCity On-Premises servers are at risk. The ACSC advises organizations to immediately check their networks for vulnerable versions and apply necessary patches. Additionally, companies should evaluate whether their TeamCity interface needs to be accessible from the internet. TeamCity, a CI/CD server used globally, streamlines software building, testing, and deployment. The vulnerability, with a critical CVSS score of 9.8, was disclosed by JetBrains in July 2026, and added to the US CISA's Known Exploited Vulnerabilities Catalog in August due to evidence of active exploitation. JetBrains has issued updates and security patches, urging customers to upgrade to versions 2025.11.7 or 2026.1.3, or install the security patch plugin without delay. Historical context reveals that TeamCity vulnerabilities have been previously exploited, including attacks by nation-state actors from Russia and North Korea.
