Zero Day Room
Live
Vulnerabilities

JetBrains Cadence Breached via Unpatched TeamCity

JetBrains disclosed a breach of its Cadence cloud service, where attackers exploited a critical TeamCity flaw to steal AWS credentials and user data.

JetBrains disclosed a breach of its Cadence cloud service, where attackers exploited a critical TeamCity flaw to steal...

JetBrains has confirmed a security breach of its Cadence cloud computing service, caused by attackers exploiting an unpatched critical vulnerability in its own TeamCity software. The intrusion, which occurred between August 8 and 24, 2026, resulted in the extraction of AWS credentials and the potential exposure of user source code and personal data.

According to the company, the threat actors exploited CVE-2026-63077, a deserialization flaw with a maximum CVSS severity score of 9.8. This vulnerability allows an unauthenticated attacker on a TeamCity server to bypass authentication and execute arbitrary commands. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had already added this flaw to its Known Exploited Vulnerabilities catalog on August 5, 2026. JetBrains discovered the exploitation on August 23.

Data and Credentials Compromised

The attackers gained access to a Cadence server backup from 2024. JetBrains stated this backup contained credentials, configuration files, artifacts, and logs. From this data, the threat actors extracted multiple AWS IAM user credentials, including those belonging to JetBrains employees who used the service.

Personal user data was also accessed. The company confirmed the following information was compromised:

Data TypeDetails
Personal DataUsernames, real names, email addresses, last-login timestamps, and last accessed IP addresses
Server BackupA full 2024 backup of the Cadence server containing credentials and configuration data
Cloud CredentialsMultiple AWS IAM users and associated secrets extracted from the backup
Cloud StorageFiles stored in S3 buckets within JetBrains AWS accounts used by Cadence

Daniel Gallo, Solutions Engineering Lead at JetBrains, said, "These findings did not identify any additional affected users. As a precaution, we are treating the data stored there as potentially exposed."

Source Code and Execution Risks

JetBrains also cautioned that attackers may have accessed source code synchronized from PyCharm projects to the compromised Cadence server. Cadence is a service that integrates with PyCharm via a plugin, allowing developers to run machine learning workloads on cloud GPUs directly from their development environment. The company warned that any project files uploaded for execution could have been exposed.

Consequently, JetBrains is instructing all Cadence users to treat every execution, along with its inputs and outputs, as potentially untrusted. The breached server, api.cadence.jetbrains.com, has been taken offline. JetBrains conceded this server should have been patched as part of its internal vulnerability response but did not explain why the update was not applied.

Indicators of Compromise and Response

JetBrains has invalidated all access tokens used by the Cadence plugin in PyCharm. It shared specific indicators for users to hunt for signs of intrusion. Key network indicators include activity from the following IP addresses associated with the attack:

  • 150.109.230.104
  • 43.153.227.206
  • 62.210.127.48
  • 210.247.242.190
  • 15.235.225.205
  • 152.233.30.18

Other compromise signals include authentication from unexpected locations, unexpected repository clones or commits, changes to repository secrets or webhooks, and unexpected access to cloud storage like AWS S3 buckets.

Mandatory User Actions

The primary directive from JetBrains is immediate credential revocation. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," the company stated. It considers any credential stored in Cadence or made available to executions on the affected server as compromised.

Beyond credential rotation, users are asked to review connected systems-including AWS accounts, S3 buckets, and deployment environments-for any suspicious activity. They should also audit source code repositories for unauthorized changes made during the intrusion period. JetBrains warned that the exposure of personal data increases the risk of targeted phishing and social engineering attacks against affected individuals. The incident response concludes with the company monitoring for further malicious activity linked to the stolen data.

Related coverage

More from Vulnerabilities