Government Advisory

Urgent: Active Attacks Targeting TeamCity Servers in Australia

ACSC · 24 Aug 2026
Key Takeaway If your business runs TeamCity On-Premise, patch immediately and check for signs of compromise, even if you think you're not a target.

The Australian Cyber Security Centre (ACSC) has raised a high alert after confirming active exploitation of a critical vulnerability affecting TeamCity On-Premise servers, a widely used software development and build management platform. The flaw, tracked as CVE-2026-63077, carries a severity score of 9.8 out of 10, indicating it is both easy to exploit and highly damaging if left unpatched.

TeamCity is commonly used by development teams to automate software builds, testing, and deployment. Because these servers often have privileged access to source code, credentials, and deployment pipelines, a successful attack could allow criminals to steal sensitive intellectual property, insert malicious code into software builds, or pivot deeper into an organisation's network.

Businesses using TeamCity On-Premise should treat this as an urgent priority. The ACSC advises organisations to immediately assess whether they are running an affected version, apply the vendor's official patch or mitigation without delay, and review server logs for signs of suspicious activity that may indicate the vulnerability has already been exploited.

TeamCity vulnerability ACSC software supply chain critical patch
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.