Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
ID: 28c0d733-405b-593a-8465-e333cb1f2d56
STIX ID: report--28c0d733-405b-593a-8465-e333cb1f2d56
Feed Name: Infosecurity Magazine (News)
Threat Score
ACSC warns that CVE-2026-63077, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in TeamCity On-Premises, is being actively exploited; JetBrains released patches and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Organizations are urged to check for vulnerable TeamCity instances, apply updates (TeamCity 2025.11.7 or 2026.1.3 or the security plugin) and avoid exposing TeamCity interfaces to the internet where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
