31 Jul 2026

Week in review

Greetings,

Organisations using JetBrains TeamCity On-Premises are being urged to patch a newly disclosed critical security vulnerability that could allow attackers to bypass authentication and execute malicious commands on affected servers. The flaw, tracked as CVE-2026-63077, impacts all versions of TeamCity On-Premises and has been rated particularly severely because it enables remote code execution with the privileges of the TeamCity server process. TeamCity Cloud customers are not affected, as mitigations have already been implemented by JetBrains.

TeamCity is widely used by development teams to automate software building, testing, and deployment processes. According to JetBrains, successful exploitation of the vulnerability could expose sensitive project data, system configurations, stored credentials, and potentially compromise software build pipelines and release artifacts. These risks make the issue especially significant for organisations that rely on TeamCity as a core component of their software delivery environment.

While JetBrains stated there is currently no evidence of active exploitation, the warning carries added weight given TeamCity’s history as a target for cybercriminals, including ransomware operators and state-sponsored threat actors in 2023 and 2024. Past vulnerabilities in the platform have been rapidly exploited in real-world attacks, prompting experts to recommend swift remediation whenever critical flaws are disclosed.

JetBrains has already addressed the issue in TeamCity versions 2025.11.7 and 2026.1.3 and strongly recommends upgrading as soon as possible. For customers unable to immediately move to the latest releases, the company has also provided a security patch plugin for supported versions dating back to TeamCity 2017.1. Additional security measures, including restricting access through VPNs and limiting exposure of internet-facing TeamCity services, are also recommended to reduce the risk of compromise.


Critical VM Escape Vulnerability Patched in VMware ESXi
Date: 2026-07-29
Author: Security Week

[AUSCERT has informed the affected members via Critical MSINs]
[AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8797/]
Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion.
Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter.
An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape.

Cisco warns of FMC static credential flaw exploited in zero-day attacks
Date: 2026-07-29
Author: Bleeping Computer

[AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8812/]
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.
The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software.
Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account.

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Date: 2026-07-25
Author: The Hacker News

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.
Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project.

US, Australia Release OT Isolation Guidance for Critical Infrastructure
Date: 2026-07-29
Author: Security Week

The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems.
Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis.
The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery.

Origin Energy boss confirms almost a million Australians compromised by data breach
Date: 2026-07-28
Author: Cyber Daily

Aussie energy supplier Origin has said it has completed its initial investigations into a cyber security incident first disclosed on 22 July.
“We have now completed the initial phase of our review into Origin’s customer data security incident,” Origin CEO Frank Calabria said in a 28 July statement.
“At this point in time, we believe the information of approximately 900,000 current and former customers was accessed.”


ESB-2026.8651 – macOS Sequoia 15.7.8: CVSS (Max): 9.1*

Apple has released security updates for macOS Sequoia 15.7.8 to address multiple security vulnerabilities. Users are advised to install the update to help protect their systems.

ESB-2026.8797 – VMware Products: CVSS (Max): 7.8

Broadcom has released security updates for VMware Aria Operations to address a high-severity local privilege escalation vulnerability.

ESB-2026.8812 – Cisco Secure FMC Software: CVSS (Max): 5.3

Cisco has released a security update for Secure Firewall Management Center (FMC) to address a critical static credential vulnerability that has been exploited in zero-day attacks.

ESB-2026.8839 – GitLab Community & Enterprise Edition: CVSS (Max): 8.5

GitLab has released GitLab 19.2.1 patch updates for Community and Enterprise Editions to address security vulnerabilities and bug fixes.

ESB-2026.8857 – Adobe Campaign Classic: CVSS (Max): 10.0

Adobe has published security updates for Adobe Campaign addressing multiple vulnerabilities. Users are advised to apply the available updates to mitigate potential security risks.


Stay safe, stay patched and have a good weekend!

The AUSCERT team