THE Australian Cyber Security Centre (ACSC) has issued a warning regarding the active exploitation of a critical vulnerability (CVE 2026-63077) affecting TeamCity On-Premises servers. This flaw allows unauthenticated attackers to bypass authentication checks and execute arbitrary OS commands. Although the ACSC has not identified specific target sectors, all organizations using the vulnerable servers are advised to review their network configurations and apply necessary patches immediately.
The vulnerability was disclosed by JetBrains in July 2026 and has a high CVSS score of 9.8, indicating its severity. The threat is compounded by evidence of ongoing exploitation, leading to its inclusion in the US Cybersecurity and Infrastructure Agency (CISA)'s Known Exploited Vulnerabilities Catalog. JetBrains has since urged users to update to the most recent versions or install security patch plugins promptly.