Run your own software build server? Patch it today
Businesses that run their own software development or build pipeline using TeamCity On-Premises, common at software companies and anywhere with an in-house or outsourced development team. Most small businesses without a dev team can skip this one.
The Australian Cyber Security Centre has issued a high alert: criminals are actively exploiting a critical flaw in TeamCity On-Premises, a continuous integration and continuous deployment (CI/CD) server that businesses use to automate building and deploying their own software. The flaw scores 9.8 out of 10 (the highest severity rating) and lets an attacker take over the server over the internet without a password. It only affects businesses that host their own TeamCity server; TeamCity Cloud customers are already protected.
Do this
Ask whoever manages your development environment: "Are we running TeamCity On-Premises, and has it been updated to version 2025.11.7 or 2026.1.3, or had JetBrains' security patch plugin applied?"
Sources: ACSC high alert ↗ · JetBrains security update ↗CVE-2026-63077 · CWE-502