High alert! ACSC warns of hackers targeting Aussie organisations using TeamCity On-Premises

The Australian Cyber Security Centre has issued a warning regarding active exploitation of a remote code execution vulnerability in JetBrains' TeamCity On-Premises software. Hackers are using the flaw to bypass authentication and execute arbitrary commands on unpatched servers.
Why it matters
This vulnerability poses a significant security risk to organizations relying on TeamCity for software delivery, necessitating immediate patching.
A month-old vulnerability in a popular software delivery platform is giving malicious actors a way into Australian networks.
Facebook X LinkedIn Copy link *]:clear-none [&>p:first-child]:font-bold [&_p:not(.momentum-promotedcontent-item_*)]:mb-5 [&_p:last-of-type:not(.momentum-promotedcontent-item_*)]:mb-5 article-content [&_a]:underline [&_a]:text-primary [&_a]:underline-offset-4 [&_div:has(iframe)]:mb-8 [&_ul]:list-disc [&_ul]:pl-6 [&_ul]:mb-5 [&_ol]:list-decimal [&_ol]:pl-6 [&_ol]:mb-5 [&_li]:mb-1 [&_li]:leading-relaxed"> The Australian Signals Directorate’s Australian Cyber Security Centre has issued a warning regarding targeted exploitation of local organisations using the TeamCity On-Premises software delivery platform.
“The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia,” the agency said late on 24 August.
According to the ACSC, hackers are utilising a recently disclosed remote code execution vulnerability , CVE-2026-63077 .
TeamCity On-Premises’ developer, JetBrains, described the vulnerability in more detail in a 28 July blog post.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in