started · updated
JetBrains warns Cadence users of breach via TeamCity vulnerability
JetBrains has issued an urgent warning to users of its Cadence cloud computing service to revoke and rotate all credentials following a security breach. Between August 8 and August 24, 2026, unidentified threat actors exploited a critical vulnerability in TeamCity, identified as CVE-2026-63077, to access the company’s environment.
The vulnerability, which carries a CVSS score of 9.8, allows unauthenticated attackers to bypass authentication and execute arbitrary operating system commands. JetBrains confirmed that attackers accessed a full 2024 server backup, which contained credentials, configuration data, and artifacts. This included multiple AWS IAM users and associated credentials, some belonging to JetBrains employees.
In addition to credentials, the breach exposed personal data such as usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses. JetBrains has invalidated all access tokens used by the Cadence plugin in PyCharm and taken the affected server offline. The company acknowledged that the server should have been patched during its initial vulnerability response but was not.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] Exposed personal data includes usernames, real names, email addresses, last-login timestamps, and last accessed IP addresses. bitnewsbot.com
- [● 2 SOURCES] Attackers exploited vulnerability CVE-2026-63077 in TeamCity to breach the Cadence environment. bitnewsbot.com · thehackernews.com
- [● 2 SOURCES] Threat actors accessed a full 2024 server backup containing credentials, configuration data, and artifacts. bitnewsbot.com · thehackernews.com
- [○ 1 SOURCE] The breach occurred between August 8 and August 24, 2026. bitnewsbot.com
- [● 2 SOURCES] CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on August 5, 2026. bitnewsbot.com · thehackernews.com
- [● 2 SOURCES] The vulnerability CVE-2026-63077 has a CVSS score of 9.8. bitnewsbot.com · thehackernews.com
- [● 2 SOURCES] The company failed to patch the affected server during its initial vulnerability response efforts. bitnewsbot.com · www.blogspan.net
- [● 2 SOURCES] JetBrains advised Cadence users to immediately revoke or rotate all credentials and secrets used in Cadence executions. bitnewsbot.com · thehackernews.com