Exploits

JetBrains Cadence Security Incident Exposes Credentials

Published  ·  5 min read

JetBrains is telling Cadence users to change all their passwords and keys right now. The company got hacked last month because attackers exploited a critical TeamCity bug to break into JetBrains' own Cadence environment.

The bug is CVE-2026-63077. It's got a CVSS score of 9.8. That's about as bad as it gets. Attackers can bypass authentication and run commands on a TeamCity server without needing any credentials. So basically, anyone who knows about this flaw can walk right in.

Attackers are already using this vulnerability in the wild. CISA added it to its Known Exploited Vulnerabilities catalog on August 5. JetBrains discovered the breach on August 23.

Here's what happened and what Cadence users need to do.

Quick Summary

What

Details

Incident

Cadence server breach

Vulnerability

CVE-2026-63077 (TeamCity)

CVSS Score

9.8

Attacker Access

August 8-24, 2026

Exposed Data

Full backup, AWS credentials, source code

Action Required

Revoke and rotate all credentials

What Is Cadence?

Cadence is JetBrains' cloud service for running machine learning and other heavy workloads on cloud GPUs. It plugs into PyCharm. It is used whenever developers need more processing power than their laptop can provide.

What Does Cadence Do?

  • Run ML and HPC jobs on GPUs in the cloud
  • Runs PyCharm
  • Keeps credentials, configurations, and project files

How Did This Occur?

The Vulnerability:

Exploits the CVE-2026-63077 vulnerability, a critical vulnerability for TeamCity that enables anyone to bypass authentication. No credentials were needed.

The Timeline:

  • August 5: CISA added the vulnerability to its KEV catalog
  • August 8: Attackers started poking around
  • August 23: JetBrains found the breach
  • August 24: The attackers stopped (or were stopped)

The Mistake:

JetBrains admitted the server should have been patched right after the vulnerability was disclosed. But they didn't patch it in time. They didn't say why.

The Server:

The affected server ("api.cadence.jetbrains.com") is now offline.

What Did the Attackers Get?

Confirmed Stolen:

  • Personal info: usernames, real names, email addresses, last-login timestamps, and IP addresses
  • A full backup of the Cadence server from 2024 with credentials, configs, artifacts, and logs
  • Multiple AWS IAM users and their credentials from that 2024 backup
  • Files stored in S3 buckets in JetBrains' AWS accounts

Possibly Stolen:

  • Source code synced from PyCharm projects
  • Any credentials or secrets stored in Cadence
  • Data from the compromised backup

Who's Affected?

JetBrains said this affects the same group of users they already contacted. No new users were added. But they're treating all data as potentially exposed to be safe.

The Risks:

  • Phishing attacks targeting affected users
  • Social engineering attempts
  • Impersonation
  • Other malicious emails or messages

What Cadence Users Need to Do

1. Change All Credentials

Assume every credential you ever stored in Cadence is compromised. Change everything.

2. View Previous Executions with Suspicion

Any process which was processed using Cadence in the specified period may have been compromised. Verify linked systems.

3. Review The Following Systems

  • AWS accounts
  • S3 buckets
  • Deployment environments
  • Package and container registries
  • Other systems which used these credentials

4. Audit Your Repositories

Search for any unauthorized change made between August 8 and August 24. Search for any odd commits.

5. Review Your IAM Roles and Policies

Review any suspicious changes in your IAM roles, policies, and permissions. Look out for any service accounts that have been created.

6. Tokens Are Already Invalidated

JetBrains already killed all access tokens used by the Cadence plugin in PyCharm.

What to Look For

Timing:

Anything that happened from August 8 onward.

Watch These IPs:

  • 150.109.230.104
  • 43.153.227.206
  • 62.210.127.48
  • 210.247.242.190
  • 15.235.225.205
  • 152.233.30.18

Suspicious Activity:

  • Logins or activity using Cadence credentials
  • Logins from unexpected IP addresses
  • Unexpected repository clones or downloads
  • Unexpected commits
  • Changes to repository secrets, webhooks, or permissions
  • New or modified access tokens, API tokens, or SSH keys
  • Unexpected cloud storage access
  • Unexpected package or release changes

The Bottom Line

JetBrains didn't patch its TeamCity server in time. Attackers exploited that and breached the Cadence service. They got a full 2024 backup with credentials and AWS IAM users. Cadence users need to change everything now.

What You Need to Know:

Key Point

Detail

Incident

Cadence server breach

Vulnerability

CVE-2026-63077 (TeamCity)

CVSS Score

9.8

Attacker Access

August 8-24, 2026

Exposed Data

Full backup, AWS credentials, source code

Action Required

Change all credentials

What You Need to Do:

  • Change all credentials
  • Treat past executions as suspicious
  • Audit your repositories
  • Review cloud IAM roles
  • Watch for suspicious activity

FAQ Section

What happened?

JetBrains' Cadence cloud service was breached through a TeamCity vulnerability. The attacker obtained a complete backup of 2024 with credentials and AWS IAM users.

Which Vulnerability Was Exploited?

CVE-2026-63077 is one of the most critical vulnerabilities in TeamCity that is rated 9.8 in CVSS. The reason for the attack is the ability of the attacker to perform some actions without needing any credentials.

Which data was breached?

Personal info (names, emails, IPs), a full 2024 Cadence backup, AWS IAM users and credentials, and S3 bucket files. Source code may also be exposed.

What should I do?

Change all credentials. Treat past Cadence executions as suspicious. Audit your repos and review IAM roles.

Who was affected?

Users who used Cadence during the affected period. JetBrains says this is the same group they already contacted.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067