ASD Notifications: Australian TeamCity Servers Undergoing Cyber Incursions


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • Major vulnerability CVE-2026-63077 in JetBrains’ TeamCity server is currently under attack in Australia.
  • This security weakness enables attackers to run arbitrary OS commands and jeopardize CI/CD pipelines.
  • CISA has included the TeamCity vulnerability in its Known Exploited Vulnerabilities listing.
  • JetBrains has released updates for serious vulnerabilities in YouTrack and IntelliJ IDEA.

TeamCity Servers in Australia Under Cyber Assault

The Australian Cyber Security Centre (ACSC) has issued an alert concerning a severe authentication bypass vulnerability in JetBrains’ TeamCity CI/CD solution. The flaw, known as CVE-2026-63077, is being actively exploited within the region.

Details on CVE-2026-63077

This vulnerability allows unauthorized attackers with HTTP/HTTPS access to execute arbitrary operating system commands on TeamCity On-Premises servers. With a severity rating of 9.8 out of 10, it presents considerable risks to CI/CD workflows by potentially undermining data integrity and revealing sensitive information.

JetBrains’ Action and Security Steps

JetBrains acknowledged the vulnerability in late July and urged users to promptly update their TeamCity versions. The company underscored the associated risks, which include exposure of TeamCity data, alteration of server states, and threats to build artifacts.

Analysis from Rapid7

Security firm Rapid7 attributed the issue to a permissive allow-list within TeamCity’s server, which deserializes Java classes from unauthorized requests. The deserialization issue stemmed from the XStream library permissions not being retracted, resulting in a vulnerability.

Implications for Global Security

The United States Cyber Security and Infrastructure Agency (CISA) has added the TeamCity vulnerability to its Known Exploited Vulnerabilities catalogue, underscoring the global importance and urgency of resolving this security issue.

JetBrains Addresses Other Vulnerabilities

Besides TeamCity, JetBrains has released fixes for critical vulnerabilities in its YouTrack and IntelliJ IDEA products. These include an issue permitting database backup downloads in YouTrack and serious vulnerabilities in IntelliJ IDEA impacting remote sessions.

Conclusion

Australian TeamCity servers are confronting serious cyber threats due to a critical vulnerability. With the issue now actively exploited, immediate action is essential to secure the affected systems. Users are encouraged to update their installations and stay alert against possible attacks.

Q&A Section

Q: What is CVE-2026-63077?

A:

CVE-2026-63077 is a major authentication bypass vulnerability in JetBrains’ TeamCity CI/CD solution, enabling unauthorized attackers to execute arbitrary OS commands.

Q: How serious is the vulnerability?

A:

This vulnerability is rated 9.8 out of 10 in severity, signifying a critical level of risk.

Q: How can users safeguard themselves?

A:

Users should promptly update their TeamCity installations and keep an eye out for any unusual activities on their servers.

Q: Has the vulnerability been exploited on a global scale?

A:

Yes, the vulnerability has been listed in CISA’s Known Exploited Vulnerabilities catalogue, indicating its global exploitation potential.

Q: Are there any other affected products?

A:

Indeed, JetBrains has also released patches for critical vulnerabilities in YouTrack and IntelliJ IDEA.

Posted by Matthew Miller

Matthew Miller is a Brisbane-based Consumer Technology Editor at Techbest covering breaking Australia tech news.

Leave a Reply

Your email address will not be published. Required fields are marked *