Critical Vulnerability in TeamCity On-Premises Servers Sparks Urgent Warning from ACSC
The Australian Cyber Security Centre (ACSC) has issued a crucial alert regarding the active exploitation of a serious vulnerability affecting TeamCity On-Premises servers, posing a significant threat to organizations utilizing this software. The vulnerability, identified as CVE 2026-63077, has the potential to allow unauthorized attackers with HTTP(S) access to bypass authentication checks and execute arbitrary commands on the operating system. This alarming issue is not limited to specific versions but affects all iterations of TeamCity On-Premises, thereby placing a wide range of Australian entities at risk.
In light of this vulnerability, the ACSC has emphasized that while no particular industry or sector is currently being targeted, all organizations utilizing TeamCity On-Premises servers in Australia are vulnerable to potential compromises. This blanket warning indicates the far-reaching implications of the flaw, prompting companies to take immediate action.
To mitigate risks, the ACSC strongly advises TeamCity users to scrutinize their networks for the presence of vulnerable versions of the software. Should any affected versions be identified, organizations are urged to promptly apply the necessary patches. Additionally, the agency has recommended that businesses consider whether it is essential to expose their TeamCity interface to the internet, an assessment that could minimize potential attack vectors.
TeamCity serves as a Continuous Integration and Continuous Deployment (CI/CD) platform, relied upon by thousands of organizations worldwide for automating essential software development processes—ranging from building and testing to deployment. Given its widespread adoption, the impact of this vulnerability could be extensive.
TeamCity Vulnerability Gains Notable Attention
The vulnerability in question, CVE 2026-63077, has received a critical severity rating of 9.8 on the Common Vulnerability Scoring System (CVSS). First disclosed by JetBrains, the software development powerhouse behind TeamCity, the vulnerability became known in July 2026 when pertinent patches were released. In a further escalation, the U.S. Cybersecurity and Infrastructure Agency (CISA) classified the vulnerability into its Known Exploited Vulnerabilities (KEV) Catalog on August 5 after observing evidence of active exploitation.
CISA has publicly stated that such vulnerabilities tend to be attractive targets for cyber adversaries and pose substantial risks, particularly to federal operations. In a follow-up notice shortly thereafter, JetBrains acknowledged reports of active exploit attempts against unpatched TeamCity servers, reinforcing the urgency of applying updates. The software company encourages any users who have yet to upgrade to TeamCity versions 2025.11.7 or 2026.1.3—or who have not yet installed the associated security patch plugin—to do so immediately.
This incident is not the first security risk to plague TeamCity. In 2024, reports surfaced regarding two vulnerabilities that were extensively exploited by attackers, with one particularly severe flaw enabling total compromise of vulnerable servers by remote unauthenticated assailants.
Additionally, in 2023, another notable vulnerability affecting TeamCity garnered attention due to targeted attacks from sophisticated actors, particularly those linked to Russian and North Korean state-sponsored efforts. This history of vulnerabilities highlights a persistent trend that merits vigilance and proactive measures from organizations utilizing this critical software.
As the situations surrounding cyber threats continue to evolve, businesses are reminded of the importance of staying informed about vulnerabilities and updates. The impact of a successful breach can be far-reaching, affecting not just individual organizations but also the supply chains and ecosystems they operate within. By prioritizing cybersecurity and promptly addressing vulnerabilities like CVE 2026-63077, organizations can protect themselves against an increasingly hostile cyber landscape.
In conclusion, the ACSC’s warning serves as a critical reminder for all businesses relying on TeamCity On-Premises software to evaluate their cybersecurity measures and ensure that they are not susceptible to potentially devastating attacks. Immediate action is required to secure systems and safeguard sensitive data against errant attempts by threat actors exploiting these critical vulnerabilities.

