type: incident ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [incident, acsc, asd, teamcity, australia, active-exploitation, ci-cd, smb] ยท confidence: high ยท affected_sectors: [government, technology, software-development] ยท au_impact: true
ACSC TeamCity Active Exploitation Alert (2026-08-24)
ASD's Australian Cyber Security Centre (ACSC) issued a high-rated alert on active exploitation of CVE-2026-63077 (Critical, CVSS 9.8) affecting all versions of JetBrains TeamCity On-Premises within Australia. An unauthenticated attacker with HTTP(S) access can bypass authentication checks and execute arbitrary operating-system commands on the CI/CD server.
Overview
| Attribute | Detail |
|---|---|
| Agency | ASD's Australian Cyber Security Centre |
| Date | 2026-08-24 |
| CVE | CVE-2026-63077 (Critical, CVSS 9.8) |
| Product | JetBrains TeamCity On-Premises โ all versions |
| Targeting | No specific industry or sector targeted |
| Audience tag | SMB |
Recommended Actions
- Review environments for vulnerable TeamCity On-Premises servers and question whether build interfaces need internet exposure at all
- Apply vendor mitigations and hunt using the vendor IoCs provided with the alert
- Check third-party and MSP-managed instances โ the alert explicitly asks organisations to confirm their providers have patched and are monitoring
Significance
The alert is the operative action for Australian organisations and outranks everything else in the day's digest. Its SMB audience tag matters because TeamCity frequently sits in small development shops rather than enterprise SOCs. The guidance reads across directly to New Zealand organisations running internet-exposed TeamCity.
Source
- ASD's ACSC โ Active Exploitation of a Software Development Platform Within Australia โ 2026-08-24
Related
- Cve 2026 63077 โ the underlying vulnerability