Two High alerts in six days, and both are management platforms
The Australian Signals Directorate's Australian Cyber Security Centre published two alerts rated High in the week to 25 August 2026. One is about a remote monitoring and management platform used by managed service providers. The other is about a build server. Neither is the sort of system most people think of as internet facing, and both were being exploited in Australia at the time the alert was written.
N-able N-central, published 19 August 2026
ASD's ACSC states the observation plainly:
ASD's ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia.
The alert describes the product as follows:
N-able N-central is a remote monitoring and management (RMM) platform. MSPs and large enterprise IT departments use it to discover, manage, automate, and secure endpoints and network infrastructure.
Two vulnerabilities are named. In the words of the alert, "CVE-2026-18556 and CVE-2026-18577 are authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel", and "The vulnerabilities affect all current versions of N-central, including 2026.3."
Patching is already available. The alert records that "Patches were released on 1 August 2026, with Hotfix 2 released on 6 August 2026. Organisations should upgrade to Hotfix 2 as a priority."
On targeting, the alert says: "ASD's ACSC has no information to indicate that a specific industry or sector is being targeted."
TeamCity On-Premises, published 24 August 2026
Five days later ASD's ACSC published a second High alert:
The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia.
The alert describes what TeamCity is: "TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software."
It describes what the vulnerability allows: "CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands."
It records the version position in one line: "This vulnerability affects all TeamCity On-Premises versions." The ASD's ACSC alerts listing rates the vulnerability itself as Critical, 9.8.
What both alerts ask organisations to do
The mitigation advice in the two alerts is close to identical, which is the useful part of reading them side by side:
- review networks and environments for use of vulnerable versions of the product;
- review the need to continue to have the interface exposed to the internet;
- where the product is managed by a third party such as an MSP or enterprise IT provider, contact that provider to confirm the products have been patched and are being monitored for suspicious activity;
- apply patches as soon as practicable, if required;
- monitor for suspicious activity, using the indicator of compromise material the vendor has released; and
- notify ASD's ACSC if suspicious activity is detected.
Both alerts give the same number for organisations that need help: "Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371)."
The question for a business that runs neither product
The N-able alert answers this one itself, and it is the sentence a small business should read first: "Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product."
The same reasoning reaches the TeamCity alert, which asks organisations to contact a third party provider where the server is managed for them. In both cases the product sits with a supplier, the exposure sits with the customer, and the answer is available for the cost of an email to the provider.
Where to read the alerts
- Active exploitation of remote monitoring and management platform within Australia, ASD's ACSC, first published 19 August 2026.
- Active exploitation of a software development platform within Australia, ASD's ACSC, first published 24 August 2026.
- Alerts and advisories, ASD's ACSC.
This article states the position as at 25 August 2026 and quotes the two alerts as published on that date. It is general information and it is not advice about any particular network.
