Skip to main content
1300 780 588 | hello@ozeit.com.au | Mon–Fri 8am–6pm AEST  Β·  24/7 Emergency Support

ACSC Warns Australian Businesses of Active Exploitation in TeamCity and N-able Tools

Recent ACSC Alerts Signal Heightened Risk

The Australian Cyber Security Centre issued high-priority warnings in August 2026 about active exploitation of vulnerabilities in TeamCity On-Premises and N-able N-central. These tools are widely used by Australian businesses and managed service providers for software builds and remote device management.

Attackers are targeting unpatched servers to gain remote code execution and bypass authentication. The flaws affect versions still in use across many small and mid-sized organisations.

What These Vulnerabilities Mean for SMBs

TeamCity is popular for continuous integration and deployment pipelines. A single compromised server can expose source code, credentials and connected systems. N-able N-central helps MSPs and internal teams manage endpoints; compromise here can lead to widespread network access.

Many 10-100 person businesses rely on these platforms or work with partners that do. The ACSC notes that no specific industry is singled out, so every organisation using the software is potentially at risk.

Practical Steps to Protect Your Business

First, identify whether your team or MSP uses TeamCity On-Premises or N-able N-central. Check current versions against the vulnerable releases listed in the ACSC advisories.

Apply the latest patches immediately. JetBrains released fixes for TeamCity in July 2026; N-able issued Hotfix 2 for N-central in early August. If you cannot patch right away, isolate the servers and monitor for suspicious activity.

Review access controls and logs for unusual logins or command execution. Enable any available indicators of compromise scripts from the vendors. SMBs should also ask their IT provider for confirmation that these tools are up to date.

Why Regular Patching Matters More Than Ever

These alerts show attackers are moving fast once vulnerabilities become public. Australian businesses cannot afford to delay updates on internet-facing or management systems.

Build a simple patching schedule that covers critical tools every month. Combine it with basic monitoring so issues surface early.

Strong patch management reduces the chance of ransomware or data theft that could disrupt operations for weeks.