JetBrains Cadence breach 2026: TeamCity CVE-2026-63077 explained

JetBrains confirmed Cadence was hit through CVE-2026-63077. The blog says the host was unpatched, personal data was taken, and a 2024 backup was compromised. The investigation is still open.

In August 2026 JetBrains confirmed that hosted Cadence was exploited through CVE-2026-63077. The orchestration layer was unpatched TeamCity, not another product line.

The 31 August 2026, 12:56 CEST update still says the investigation is open. The rest is a check of who, when, and what was taken — not a runbook.

Official noticeTimelineExposure

What the public post prints

8/8–24
Affected period in the notice
8/31
Latest stamped blog update
2024
Year of the full backup taken
ItemOfficial wordingBoundary
Hostapi.cadence.jetbrains.comIncident limited to data tied to this host, for now
CVECVE-2026-63077TeamCity On-Premises; Cloud needed no action in July
Find / offlineFound 23 Aug, offline 24 AugActivity dated from 8 August
Current envNo evidence secrets were pulled31 Aug update; investigation open

How to read the incident

  1. 1

    The product is Cadence; the hole is TeamCity

    Cadence is hosted compute behind an optional PyCharm plugin. The notice says TeamCity orchestrates jobs. July fixes were 2025.11.7 and 2026.1.3, plus a security-patch plugin.

  2. 2

    The miss is stated plainly

    Quote from the post: the server should have been patched as part of the response, but it was not. Offline plus plugin-token invalidation landed on 24 August.

  3. 3

    Personal data and the backup are confirmed

    Usernames, real names, emails, last-login times, and last-access IPs were extracted. A full 2024 backup was compromised. Credentials, config, artifacts, and logs in that backup are to be treated as exposed.

  4. 4

    The cloud side is still being written

    AWS IAM users in the backup, including some employees, were compromised. Cadence S3 objects in JetBrains AWS accounts were accessed. Customer-owned buckets: the post says it does not yet know.

What else the notice flags

01

Advice to users

Rotate secrets that may have run Cadence jobs. Treat execution inputs and outputs as untrusted. Review cloud accounts, repos, and files synced from PyCharm.

02

The credential list is long

The post names cloud vendors, GitHub/GitLab/Bitbucket, npm/Maven/NuGet/PyPI, container registries, plus Slack, webhooks, SSH, and signing keys.

03

IoCs are not a clean bill

Several exploitation-related IPs are listed. The list is not exhaustive. Missing those indicators does not prove a system was untouched.

Limits

The post does not close customer-S3 scope or end the investigation. If you only needed a short meeting without another account wall, wbstorm is a browser room ID — see also privacy without an account and create or join a room.

# Sources
# JetBrains Blog, 2026-08-31: Security Incident Affecting JetBrains Cadence
# JetBrains TeamCity Blog, 2026-07: CVE-2026-63077
Was TeamCity Cloud affected?

The July advisory said TeamCity Cloud customers needed no action. This incident is about unpatched TeamCity inside hosted Cadence.

Were live production secrets extracted?

The 31 August update says there is no evidence data including secrets was pulled from the current Cadence environment. The backup and personal data are confirmed. The investigation is open.

Is this a product how-to?

No. It only checks the public incident text. It does not give exploit or response steps.

Create room