← All briefings

A critical flaw for anyone running their own software build server

Week of 24 to 30 August 2026

A busy week: a critical, actively-exploited flaw hit TeamCity, the tool many software teams use to build their own applications; Citrix NetScaler, the appliance many mid-sized businesses use for remote access, joined the actively-exploited list with a three-day patch deadline; Oracle's web server software and the Gitea code-hosting server carried maximum-severity flaws too; an old Microsoft SQL Server bug, patched back in 2019, was newly confirmed under active attack; and a 2023 flaw in ownCloud, self-hosted file storage software, was added to the same list. If your business doesn't run its own build server, remote-access gateway, database, web server, code repository or self-hosted file-sync server, none of this week's news applies to you.

  1. 1

    Run your own software build server? Patch it today

    Businesses that run their own software development or build pipeline using TeamCity On-Premises, common at software companies and anywhere with an in-house or outsourced development team. Most small businesses without a dev team can skip this one.

    The Australian Cyber Security Centre has issued a high alert: criminals are actively exploiting a critical flaw in TeamCity On-Premises, a continuous integration and continuous deployment (CI/CD) server that businesses use to automate building and deploying their own software. The flaw scores 9.8 out of 10 (the highest severity rating) and lets an attacker take over the server over the internet without a password. It only affects businesses that host their own TeamCity server; TeamCity Cloud customers are already protected.

    Do this

    Ask whoever manages your development environment: "Are we running TeamCity On-Premises, and has it been updated to version 2025.11.7 or 2026.1.3, or had JetBrains' security patch plugin applied?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: ACSC high alert ↗ · JetBrains security update ↗CVE-2026-63077 · CWE-502

  2. 2

    Staff work remotely through Citrix? It needs an urgent patch

    Businesses using Citrix NetScaler ADC or NetScaler Gateway configured for remote access (VPN, ICA Proxy or RDP Proxy), typically mid-sized businesses with their own network appliance, not smaller businesses using a simpler remote-access tool. If the name Citrix NetScaler doesn't ring a bell, you're not running it.

    Citrix NetScaler ADC and NetScaler Gateway, the appliance many mid-sized businesses use to let staff connect in remotely, has a flaw that criminals are now actively exploiting. They can send it something that crashes or destabilises the gateway over the internet without needing a password, cutting off remote access for however long it takes to recover. Citrix has released a fix, and the flaw is serious enough that US cyber security authorities gave a three-day deadline to patch it.

    Do this

    Ask your IT provider: "Are we running Citrix NetScaler ADC or Gateway for remote access, and has it been updated to 13.1-63.18, 14.1-72.61, or later?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: Citrix NetScaler flaw ↗ · Citrix security advisory ↗CVE-2026-8452 · CWE-119

  3. 3

    Self-host file storage with ownCloud? Confirm it's patched since 2023

    Businesses that self-host their own ownCloud server for file storage and sharing, running ownCloud Core versions 10.6.0 through 10.13.0 (an option some choose over cloud services like Dropbox or OneDrive for cost or data-residency reasons). If your files live in Microsoft 365, Google Workspace or a mainstream cloud storage service, this one isn't yours to worry about.

    ownCloud, self-hosted software some businesses run instead of Dropbox or OneDrive to keep file storage and sharing under their own control, has a flaw that lets an attacker read, change or delete any file without a password, as long as they know a valid username. It works through specially crafted web links that the software accepts even when the file owner hasn't set up a signing key to protect them, which is the default setting. ownCloud fixed this in November 2023, but the flaw has only now been added to the US government's list of vulnerabilities criminals are actively exploiting, usually a sign that unpatched servers are still being found and targeted.

    Do this

    Ask whoever manages your file storage: "Are we running ownCloud, and has it been updated to version 10.13.1 or later?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: ownCloud flaw ↗ · ownCloud security advisory ↗CVE-2023-49105 · CWE-287

  4. 4

    Run Oracle HTTP Server or WebLogic? Patch it now (most small businesses can skip this one)

    Businesses running their own Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in, typically larger organisations or those with a custom-built enterprise web application, not standard small business software. If neither name means anything to you, you're not running it.

    The US Cybersecurity and Infrastructure Security Agency has added a flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in to its list of vulnerabilities criminals are actively exploiting. The flaw scores 10 out of 10 (the maximum possible severity) and lets an attacker access, create, delete or change data on the server over the internet without a password or any user interaction. Oracle fixed it in its January 2026 security update; the risk now sits with any server that update was never applied to.

    Do this

    Ask whoever manages your web infrastructure or custom applications: "Are we running Oracle HTTP Server or WebLogic Server Proxy Plug-in, and has January 2026's Critical Patch Update for CVE-2026-21962 been applied?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: Oracle HTTP Server/WebLogic flaw ↗ · Oracle January 2026 Critical Patch Update ↗CVE-2026-21962 · CWE-284

  5. 5

    Run your own Microsoft SQL Server? Confirm it's been patched since 2019

    Businesses running their own on-premises Microsoft SQL Server for line-of-business software: accounting, ERP, or custom applications built in-house. Not relevant if SQL Server has been kept patched since 2019, or if your database runs as a fully managed cloud service.

    Microsoft SQL Server has a flaw that lets someone who already has some access to your database (for example, through a compromised staff account) run their own code and take full control of the server. Microsoft fixed it back in July 2019, but criminals have only now been confirmed to be actively exploiting it, which usually means they've found unpatched systems still worth targeting. It affects on-premises SQL Server 2014 through 2017.

    Do this

    Ask whoever manages your SQL Server: "Has SQL Server been updated with Microsoft's July 2019 security update for CVE-2019-1068, or a later cumulative update?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: Microsoft SQL Server flaw ↗ · Microsoft security advisory ↗CVE-2019-1068

  6. 6

    Self-host your team's code in Gitea? Update it this week

    Businesses that self-host a Gitea server for their own code, mostly small software or development teams. If your code lives on GitHub, GitLab or Bitbucket's cloud services, this one is not yours to worry about.

    Gitea, free software many small development teams use to host their own code repositories instead of paying for GitHub or GitLab, has a flaw that lets an attacker run commands on the server. It has joined the US Cybersecurity and Infrastructure Security Agency's list of vulnerabilities being actively exploited. An attacker needs write access to a repository to exploit it, and on a default Gitea setup with open sign-ups, anyone can get that by registering an account. A fix has been available since July 2026.

    Do this

    Ask whoever manages your development environment: "Are we running Gitea, is it updated to version 1.27.1 or later, and is public account registration turned off?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: Gitea flaw ↗ · Gitea security advisory ↗CVE-2026-60004 · CWE-94

Beyond this week's news

Reading about threats is step one. Knowing where you stand is step two.

See whether the security products you already pay for cover the basics (free, in about three minutes), or get a fixed-price, plain-English review of your whole setup.

Prefer LinkedIn? Follow TERESEC: the briefing lands there every Monday.

Latest ISM release: ISM September 2026: What Changed and What to Check →What the ISM is and how we assess it →