ACSC warns of active exploitation of TeamCity servers in Australia

The Australian Cyber Security Centre (ACSC) has issued a high-severity alert warning that it has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia.

ACSC warns of active exploitation of TeamCity servers in Australia

ACSC warns of active exploitation of TeamCity servers in Australia


The Australian Cyber Security Centre (ACSC) has issued a high-severity alert warning that it has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia.

The ACSC said the alert is relevant to all Australian organisations using TeamCity On-Premises, a continuous integration and continuous deployment (CI/CD) platform used to automate building, testing and deploying software.

According to the alert, CVE-2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands. The ACSC said the issue affects all TeamCity On-Premises versions.

The agency said it has no information indicating that a specific industry or sector is being targeted, but warned organisations to review their environments for use of vulnerable versions and assess whether TeamCity interfaces need to be exposed to the internet.

As mitigation steps, the ACSC advised organisations to review the vendor’s support guidance, apply patches as soon as practicable, and monitor for suspicious activity. The alert noted that indicators of compromise have been released by the vendor, which may assist in detecting malicious activity.

The ACSC also urged organisations using third-party managed TeamCity services—such as through a managed service provider or enterprise IT provider—to confirm patching and monitoring arrangements. It asked organisations to notify the ACSC if suspicious activity is detected.

The alert was published on 24 August 2026 on Cyber.gov.au.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.