JetBrains Cadence breach 2026: TeamCity CVE-2026-63077 explained
JetBrains confirmed Cadence was hit through CVE-2026-63077. The blog says the host was unpatched, personal data was taken, and a 2024 backup was compromised. The investigation is still open.
In August 2026 JetBrains confirmed that hosted Cadence was exploited through CVE-2026-63077. The orchestration layer was unpatched TeamCity, not another product line.
The 31 August 2026, 12:56 CEST update still says the investigation is open. The rest is a check of who, when, and what was taken — not a runbook.
What the public post prints
| Item | Official wording | Boundary |
|---|---|---|
| Host | api.cadence.jetbrains.com | Incident limited to data tied to this host, for now |
| CVE | CVE-2026-63077 | TeamCity On-Premises; Cloud needed no action in July |
| Find / offline | Found 23 Aug, offline 24 Aug | Activity dated from 8 August |
| Current env | No evidence secrets were pulled | 31 Aug update; investigation open |
How to read the incident
- 1
The product is Cadence; the hole is TeamCity
Cadence is hosted compute behind an optional PyCharm plugin. The notice says TeamCity orchestrates jobs. July fixes were 2025.11.7 and 2026.1.3, plus a security-patch plugin.
- 2
The miss is stated plainly
Quote from the post: the server should have been patched as part of the response, but it was not. Offline plus plugin-token invalidation landed on 24 August.
- 3
Personal data and the backup are confirmed
Usernames, real names, emails, last-login times, and last-access IPs were extracted. A full 2024 backup was compromised. Credentials, config, artifacts, and logs in that backup are to be treated as exposed.
- 4
The cloud side is still being written
AWS IAM users in the backup, including some employees, were compromised. Cadence S3 objects in JetBrains AWS accounts were accessed. Customer-owned buckets: the post says it does not yet know.
What else the notice flags
Advice to users
Rotate secrets that may have run Cadence jobs. Treat execution inputs and outputs as untrusted. Review cloud accounts, repos, and files synced from PyCharm.
The credential list is long
The post names cloud vendors, GitHub/GitLab/Bitbucket, npm/Maven/NuGet/PyPI, container registries, plus Slack, webhooks, SSH, and signing keys.
IoCs are not a clean bill
Several exploitation-related IPs are listed. The list is not exhaustive. Missing those indicators does not prove a system was untouched.
Limits
The post does not close customer-S3 scope or end the investigation. If you only needed a short meeting without another account wall, wbstorm is a browser room ID — see also privacy without an account and create or join a room.
# Sources
# JetBrains Blog, 2026-08-31: Security Incident Affecting JetBrains Cadence
# JetBrains TeamCity Blog, 2026-07: CVE-2026-63077Was TeamCity Cloud affected?
The July advisory said TeamCity Cloud customers needed no action. This incident is about unpatched TeamCity inside hosted Cadence.
Were live production secrets extracted?
The 31 August update says there is no evidence data including secrets was pulled from the current Cadence environment. The backup and personal data are confirmed. The investigation is open.
Is this a product how-to?
No. It only checks the public incident text. It does not give exploit or response steps.