JetBrains Confirms TeamCity Exploitation in Cadence Breach

Attackers exploited a critical TeamCity flaw in an attack on JetBrains Cadence. Affected users should rotate all secrets and credentials used in Cadence.

CVE-2026-63077 TeamCity was reportedly exploited in the breach of Cadence, a service designed for cloud-based runs, according to JetBrains. The attackers gained access to api.cadence.jetbrains.com, where JetBrains recorded their activity starting August 8, 2026. The company took the server offline on August 24; in its latest public update on September 3, it added information about exfiltrated personal data and other data that may have been exposed.

The CVE-2026-63077 vulnerability enables unauthenticated command execution on vulnerable TeamCity On-Premises installations through the agent polling protocol. This is therefore confirmed exploitation of a critical flaw in CI/CD infrastructure, not merely a theoretical scenario.

CVE-2026-63077 TeamCity: What the Attackers Obtained

JetBrains said the attackers obtained and exfiltrated Cadence users’ personal data. This included usernames, names, email addresses, last-login information, and IP addresses.

A complete backup of the Cadence server from 2024 was also compromised during the incident. According to JetBrains, it contained multiple AWS IAM identities and related credentials used by the Cadence service.

On September 3, the company added that the attacker gained access that could have enabled access to storage containing emails, project source code, and credentials of current Cadence users. According to JetBrains, this group of users has already been contacted.

However, JetBrains did not confirm that source code or credentials from the current storage were demonstrably exfiltrated. It considers them potentially exposed. It is also not publicly known who carried out the attack or what their motive was.

Affected Users Should Rotate Secrets

JetBrains invalidated Cadence plugin access tokens in PyCharm. It also recommends that users immediately revoke or rotate all secrets and credentials used in Cadence runs.

This includes cloud, repository, package, and registry credentials, as well as other secrets available to the Cadence environment. The compromised backup and affected environment could have contained such data.

It has not been confirmed whether the attackers accessed S3 buckets in customers’ AWS accounts. Based on the available information, the risk primarily concerns users who configured Cadence with their own cloud credentials.

Fixes for TeamCity On-Premises

Fixes for CVE-2026-63077 TeamCity are available in TeamCity versions 2025.11.7 and 2026.1.3. For installations from version 2017.1 onward, JetBrains provided a security patch plugin.

TeamCity On-Premises administrators should deploy the relevant fix or patch plugin and check the environment for possible signs of unauthorized activity, including logs and build agents. JetBrains said it received reports of active exploitation of unpatched servers.

Further information may concern the precise scope of exfiltration from the current Cadence storage, possible indicators of compromise, and evidence of the use of compromised AWS IAM credentials.

Sources

Verified and updated: 09/05/2026 21:19

Sharing