type: cve ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [cve, jetbrains, teamcity, auth-bypass, rce, ci-cd, actively-exploited, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, devops, software-development] ยท au_impact: true
CVE-2026-63077
CVE-2026-63077 is a critical authentication-bypass vulnerability (CVSS 9.8) affecting all versions of JetBrains TeamCity On-Premises. ASD's Australian Cyber Security Centre (ACSC) has observed active exploitation within Australia: an unauthenticated attacker with HTTP(S) access can bypass authentication checks and execute arbitrary operating-system commands on the CI/CD server.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-63077 |
| Product | JetBrains TeamCity On-Premises (all versions) |
| CVSS | 9.8 (Critical) |
| Type | Unauthenticated authentication bypass โ OS command execution |
| Precondition | HTTP(S) network access to the server |
| Exploitation | Actively exploited within Australia (ACSC alert, 2026-08-24) |
Australian Context
The ACSC alert reports no specific industry or sector being targeted. TeamCity frequently sits in small development shops rather than enterprise SOCs, so the alert carries an SMB audience tag. Compromise of a TeamCity server can expose source code, build artifacts, deployment credentials and downstream production environments.
Mitigation
- Review environments for vulnerable TeamCity On-Premises servers and question whether build interfaces need internet exposure at all
- Apply vendor mitigations and hunt using the vendor IoCs provided with the alert
- Check third-party and MSP-managed instances โ the alert explicitly asks organisations to confirm their providers have patched and are monitoring
Source
- ASD's ACSC โ Active Exploitation of a Software Development Platform Within Australia โ 2026-08-24
Related
- Acsc Teamcity Active Exploitation Alert 2026 08 24 โ ACSC alert incident note