The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia.
Background
The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia. TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software. The vulnerability, identified as CVE 2026-63077, may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.
Mitigation Advice
The ASD’s ACSC advises organisations to review networks and environments for use of vulnerable versions of the TeamCity On-Premises server, review the need to continue to have the interface exposed to the internet, and apply patches as soon as practicable, if required. Organisations should also monitor for suspicious activity and contact their managed service provider if TeamCity Server is managed by a third party.
Why it may matter locally
Australian healthcare organisations and Melbourne businesses should review their use of TeamCity On-Premises servers and verify that patches have been applied. They should also check for suspicious activity and review their network configurations to ensure the interface is not unnecessarily exposed to the internet. The IT support team should be notified to perform these checks and apply any necessary patches.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
