Skip to main content
Emerging ThreatsMalware & Ransomware

Australian Cyber Agency Warns of Widespread TeamCity Server Exploit

Rows of computer servers and networking equipment in a brightly-lit server room with technicians in the background.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned — a stark assessment that now accompanies an Australian alert about active exploitation of a critical TeamCity server flaw.

CVE 2026-63077: what the flaw allows

The vulnerability tracked as CVE 2026-63077 permits unauthenticated attackers with HTTP(S) access to a TeamCity On‑Premises server to bypass authentication checks and execute arbitrary operating system commands. The Australian Cyber Security Centre (ACSC) said the flaw affects all TeamCity On‑Premises versions. Assigned a critical CVSS score of 9.8, the weakness creates a path for remote compromise without prior credentials.

ACSC and CISA warnings and timeline

The ACSC warned that threat actors are actively exploiting the flaw and urged Australian organisations that use TeamCity On‑Premises to urgently review their networks and apply fixes where necessary. The agency additionally advised organisations to consider whether their TeamCity interface needs to be exposed to the internet.

CVE 2026-63077 was added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on August 5, 2026, a move CISA made after finding evidence of active exploitation. CISA’s public comment quoted above framed the vulnerability as a recurring and serious attack vector for malicious actors and as posing substantial risks to the federal enterprise.

JetBrains' patches and customer guidance

JetBrains — the owner of TeamCity — first disclosed the vulnerability in July 2026 when it issued patches. Two days after CISA’s KEV listing, JetBrains published a follow‑up advisory reporting that it had received reports of active exploitation and attempted exploitation against unpatched TeamCity servers.

JetBrains told customers that those who have not updated to TeamCity 2025.11.7 or 2026.1.3, or who have not installed the vendor’s security patch plugin, should do so immediately. The vendor’s guidance centers on applying the available fixes and reducing exposure of on‑premises interfaces.

Past targeting of TeamCity and attacker interest

TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server used by thousands of organisations worldwide to automate building, testing and deploying software on a single system. The software’s role in software supply chains and build processes helps explain why flaws in TeamCity are attractive to attackers.

Security reporting recounted further history: in 2024 two vulnerabilities affecting TeamCity On‑Premises were being extensively exploited, and the most severe of those allowed a complete compromise of a vulnerable TeamCity server by a remote unauthenticated attacker. Additionally, a critical vulnerability disclosed in 2023 was found to have been targeted by Russian and North Korean nation‑state actors — a precedent that underlines the operational interest in TeamCity flaws.

What this means for technologists, policymakers, and enterprises

  • Technologists and security teams: Review networks for on‑premises TeamCity instances, confirm whether the interface is internet‑exposed, and apply the patches or the security patch plugin cited by JetBrains to mitigate CVE 2026-63077.
  • Policymakers and regulators: CISA’s addition of CVE 2026-63077 to the KEV Catalog and its public warning frames the flaw as a federal‑level risk; agencies and regulatory bodies will track remediation status and exploit activity as part of enterprise risk assessments.
  • Affected enterprises and procurement leaders: Organisations that use TeamCity — the ACSC noted all Australian organisations using TeamCity On‑Premises are at risk — must prioritize patching, reassess internet exposure of CI/CD infrastructure, and consider whether procurement and deployment practices limit unnecessary external access to build systems.

The record from JetBrains, CISA and the ACSC is plain: a high‑severity, easily reachable flaw in widely used CI/CD software is being exploited in the wild. With patches published and a KEV listing in place, the immediate measure is remediation; the persistent questions are operational — how many instances remain unpatched, and how many organisations will decide to remove unnecessary internet exposure for their TeamCity servers. Those answers will determine whether this episode is contained or becomes another chapter in the history of CI/CD exploitation.

https://www.infosecurity-magazine.com/news/australia-exploitation-teamcity/