Key points
- The ACSC is warning that CVE-2026-63077, a critical authentication bypass in JetBrains' TeamCity On-Premises server, is under active local attack.
- Rated 9.8 out of 10 in severity, the flaw lets unauthenticated attackers with HTTP/HTTPS access run arbitrary OS commands and compromise CI/CD pipelines.
- CISA has added the TeamCity flaw to its Known Exploited Vulnerabilities catalogue, while JetBrains has also patched critical bugs in YouTrack and IntelliJ IDEA.
An authentication bypass in JetBrains' continuous integration/continuous deployment (CI/CD) platform TeamCity is under attack locally, the Australian Cyber Security Centre (ACSC) is warning.
The Australian Signals Directorate's ACSC said the flaw, tracked as CVE-2026-63077, allows an unauthenticated attacker with HTTP/HTTPS access to a TeamCity On-Premises server to run arbitrary operating system commands.
JetBrains confirmed the critical vulnerability in late July this year, urging users to update their TeamCity installations.
"Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines," JetBrains wrote.
In July, JetBrains said it hadn't seen any exploit attempts of the vulnerability which is rated as 9.8/10 for severity, but ASD's ACSC now says that has changed, although the agency did not provide further details on the attacks.
Security vendor Rapid7 analysed the bug, and traced the problem to a permissive allow-list that governs which Java classes the server should deserialise from unauthenticated agent requests.
TeamCity's own protocol classes were added to the server's allow-list, without the underlying XStream serialisation library permissions first being removed; this which introduced an unsafe deserialisation issue, Rapid7 researcher Stephen Fewer wrote.
Fewer also published proof-of-concept code for the vulnerability on GitHub.
The United States Cyber Security and Infrastructure Agency (CISA) has added the TeamCity flaw to its Known Exploited Vulnerabilities (KEV) must-fix catalogue.
Outside the cyber security agency alerts, JetBrains this month issued patches for a critical vulnerability in the YouTrack product, that could allow an unauthenticated attacker to download database backups via a shared draft signature (CVE-2026-75045), rated as 9.1 out of 10.
Prior to that, in July JetBrains disclosed two 10/10 critical flaws in its IntelliJ IDEA flagship integrated development environment, CVE-2026-64812 and CVE-2026-64813, affecting remote sessions.

NiCE World APAC 2026
The 2026 iAwards
Integrate 2026
Security Exhibition & Conference
NiCE World APAC 2026



