Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

High alert! ACSC warns of hackers targeting Aussie organisations using TeamCity On-Premises

A month-old vulnerability in a popular software delivery platform is giving malicious actors a way into Australian networks.

Tue, 25 Aug 2026
High alert! ACSC warns of hackers targeting Aussie organisations using TeamCity On-Premises

The Australian Signals Directorate’s Australian Cyber Security Centre has issued a warning regarding targeted exploitation of local organisations using the TeamCity On-Premises software delivery platform.

“The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia,” the agency said late on 24 August.

According to the ACSC, hackers are utilising a recently disclosed remote code execution vulnerability, CVE-2026-63077.

 
 

TeamCity On-Premises’ developer, JetBrains, described the vulnerability in more detail in a 28 July blog post.

“If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said.

“All versions of TeamCity On-Premises are affected. TeamCity Cloud customers are not required to take any action, as the necessary measures have already been applied.”

At the time, JetBrains said it had found no evidence of active exploitation, though, clearly, that has now changed, which the company addressed in a later blog post.

“Since our initial announcement on July 27, 2026, we have received reports of active exploitation, as well as attempted exploitation, targeting unpatched TeamCity servers,” JetBrains said on 7 August.

“We strongly recommend that customers who have not yet updated to TeamCity 2025.11.7 or 2026.1.3, or installed the security patch plugin, do so immediately.”

“We have also released a security patch plugin for 2017.1+ so that customers who are unable to upgrade can still patch their environments.”

The ACSC has the following recommendations for users of TeamCity On-Premises:

  • Review environments for use of vulnerable versions of the TeamCity On-Premises server.
  • Review the need to have the interface exposed to the internet.
  • Review the mitigation advice on the vendor’s support page.
  • If managed by a third party, such as an MSP or enterprise IT provider, organisations should contact that provider to ensure the products have been patched and are being monitored for suspicious activity.
  • Apply patches as soon as practicable.
  • Monitor for suspicious activity.
  • If suspicious activity is detected, notify ASD’s ACSC.
Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: