JetBrains Cadence Exploitation via TeamCity CVE-2026-63077
Score: 7/10

JetBrains Cadence Exploitation via TeamCity CVE-2026-63077

Unauthorized threat actors exploited a critical vulnerability (CVE-2026-63077) in the JetBrains Cadence service to access customer source code, credentials, and personal data.

Executive Summary

Between August 8 and August 24, 2026, JetBrains Cadence, a hosted cloud compute service for PyCharm, was compromised by unknown threat actors. The attackers exploited CVE-2026-63077, a critical vulnerability in the underlying TeamCity orchestration engine that allows unauthenticated remote command execution.

The investigation confirmed that the adversary accessed a full server backup from 2024 and potentially the current production environment. Impacted data includes project source code, customer email addresses, real names, last-login metadata, and sensitive credentials including AWS IAM keys and S3 bucket contents. JetBrains has taken the affected API endpoint offline and invalidated plugin access tokens.

This incident represents a significant risk to organizations utilizing Cadence for automated workflows, as exposed credentials could facilitate lateral movement into customer-owned AWS, GitHub, or package registry environments. Immediate rotation of all secrets used within the service is required.

Key Details

Threat Name

CVE-2026-63077

Affects

JetBrains TeamCity, JetBrains Cadence

Adversary

—

Malware/Tools

None identified

Report Score

7out of 10
Quality Score
Good
IOC Quality7
TTP Details6
Detection Guidance5
Enterprise Relevance9
Clarity & Structure9
Technical Depth4

Sources