JetBrains Cadence Breach via Unpatched TeamCity
JetBrains, a prominent software development company, has confirmed a significant security incident impacting its Cadence cloud computing service. Unidentified threat actors exploited a critical, unpatched vulnerability in TeamCity, an integral part of JetBrains’ own infrastructure, to breach Cadence environments. This compromise led to the unauthorized access and potential exposure of sensitive data, including AWS credentials, user email addresses, and project source code, according to The Hacker News.
Cadence is a specialized JetBrains-hosted service designed for machine learning and heavy workloads, integrating seamlessly with PyCharm via an optional plugin. The incident underscores the critical importance of timely patching, even within an organization’s internal systems, and necessitates immediate action from all Cadence users.
CVE-2026-63077 Unpatched TeamCity Exploitation and Data Compromise
The attack vector was identified as the exploitation of CVE-2026-63077, a deserialization of untrusted data vulnerability with a CVSS score of 9.8. This critical flaw allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026, indicating active exploitation in the wild.
JetBrains discovered the exploitation on August 23, 2026, tracing the intrusion window to between August 8 and August 24, 2026. The company acknowledged that the compromised server, api.cadence.jetbrains.com, should have been patched as part of its internal vulnerability response, but no details were provided regarding this oversight.
The breach granted threat actors access to data contained in a Cadence server backup from 2024 and unauthorized access to storage potentially holding data associated with current Cadence users. Confirmed compromised data includes:
- Credentials and Secrets: Any credentials or secrets stored in Cadence, contained in the compromised backup, or made available to executions on the affected server, including AWS credentials.
- User Information: Email addresses of affected Cadence users.
- Project Source Code: Source code synchronized from PyCharm projects to the affected Cadence server, where users relied on PyCharm to upload or synchronize project files for execution.
- Execution Inputs/Outputs: Inputs and outputs of Cadence project executions should be considered potentially untrusted.
Impact on JetBrains Cadence Users and Associated Systems
The exposure of credentials and source code presents a severe risk. Attackers could leverage compromised AWS credentials to access cloud resources, escalate privileges, and potentially deploy malicious infrastructure or exfiltrate further data. The access to project source code could lead to intellectual property theft, discovery of further vulnerabilities in user applications, or tampering with software supply chains.
For affected users, the personal data exposure, specifically email addresses, carries a high risk of targeted phishing, social engineering, and impersonation attempts. These secondary attacks can lead to further compromises, extending the impact beyond the initial breach. The JetBrains Cadence plugin in PyCharm also had its access tokens invalidated, requiring users to re-authenticate or generate new tokens.
Immediate Remediation and Long-Term Security Posture
JetBrains has provided urgent recommendations for all Cadence users to mitigate the immediate risks of the JetBrains Cadence breach mitigation steps. These actions are critical to contain potential damage:
- Credential Revocation and Rotation: Immediately revoke or rotate all credentials and secrets that may have been used to run Cadence executions or were stored within the service. This specifically includes any AWS credentials, API keys, or other sensitive access tokens.
- System Audit: Conduct a thorough review of all connected systems for suspicious activity. Pay close attention to:
- AWS accounts and S3 buckets.
- Deployment environments.
- Package and container registries.
- Other systems accessible using the revoked credentials.
- Source Code Review: Audit source code repositories for any unauthorized changes or introductions of malicious code during the breach period (August 8 – 24, 2026).
- Treat Executions as Untrusted: Consider all executions, including their inputs and outputs, within your Cadence project as potentially compromised and untrusted.
Organizations should also consider implementing enhanced monitoring for their cloud environments, especially those integrated with developer tools, to detect anomalous activity indicative of revoked AWS credentials after Cadence breach or other forms of post-exploitation. This incident serves as a stark reminder that even well-known software vendors can fall victim to critical vulnerabilities, emphasizing the continuous need for vigilance and a proactive security posture across the entire development and deployment pipeline.
Related: TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million, Mount Royal University Data Breach: Network Intrusion, Data Theft, and Deletion