www.infosecurity-magazine.com 8/25/2026, 11:20:49 AM · external

ACSC Warns of Active TeamCity Exploits via CVE-2026-63077

ACSC Warns of Active TeamCity Exploits via CVE-2026-63077
Developing story malware 19 articles tracked
JetBrains TeamCity unauthenticated RCE exploited via CVE-2026-63077
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov

THE Australian Cyber Security Centre (ACSC) has issued a warning regarding the active exploitation of a critical vulnerability (CVE 2026-63077) affecting TeamCity On-Premises servers. This flaw allows unauthenticated attackers to bypass authentication checks and execute arbitrary OS commands. Although the ACSC has not identified specific target sectors, all organizations using the vulnerable servers are advised to review their network configurations and apply necessary patches immediately.

The vulnerability was disclosed by JetBrains in July 2026 and has a high CVSS score of 9.8, indicating its severity. The threat is compounded by evidence of ongoing exploitation, leading to its inclusion in the US Cybersecurity and Infrastructure Agency (CISA)'s Known Exploited Vulnerabilities Catalog. JetBrains has since urged users to update to the most recent versions or install security patch plugins promptly.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline