Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for critical TeamCity CVE-2026-63077 remote code execution vulnerability with CVSS 9.8 rating

TeamCity RCE Flaw Hits CISA Deadline — Ask Your Developer If They’ve Patched

CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalogue on 5 August and set a federal patch deadline of today, 8 August. The bug is a CVSS 9.8 unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises — the CI/CD server that thousands of development teams use to build and ship software. An attacker with network access can bypass authentication entirely, run commands on the server, and steal every stored credential in the pipeline.

Most Australian SMBs don’t run TeamCity themselves, but there’s a good chance someone in your supply chain does. Your web developer, your app vendor, the agency that built your booking system — if any of them use TeamCity and haven’t patched, an attacker could tamper with the code those providers ship to you. That’s a supply chain compromise, and you’d never see it coming from your own security logs. We see this pattern regularly across our managed IT client base: businesses outsource development work but never ask a single question about the security of the toolchain that builds it.

If you commission software or websites from an external team, ask them directly: “Do you use JetBrains TeamCity? If so, have you updated to version 2025.11.7 or 2026.1.3?” If they use TeamCity Cloud, they’re fine — the cloud-hosted version isn’t affected. If they’re on-premises and haven’t patched, they should do so immediately. JetBrains also offers a security patch plugin for teams that can’t upgrade right away.

Supply chain risk is one of the hardest things for a small business to manage alone. If you’d like help auditing your vendor relationships and the tools they use, our managed IT team can run a third-party risk check as part of your ongoing security posture.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →