JetBrains has called on all Cadence users to revoke and rotate their credentials following a significant security breach. The incident involved unidentified attackers exploiting a critical vulnerability in TeamCity, specifically CVE-2026-63077, allowing them unauthorized access to JetBrains' Cadence environment. This vulnerability, which scores a high 9.8 on the CVSS scale, enabled attackers to bypass authentication checks and execute arbitrary commands on the server.
The breach, discovered by JetBrains on August 23, 2026, has had wide-reaching implications. Threat actors accessed sensitive data from a Cadence server backup dating back to 2024 and potentially reached storage with data from current Cadence users. This data includes email addresses, source code, and AWS credentials. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added the vulnerability to its Known Exploited Vulnerabilities catalog, underscoring the severity of the threat.
JetBrains is treating all data on the compromised server as potentially exposed. This includes scenarios where users synchronized source code from PyCharm projects to Cadence, which might have led to inadvertent exposure of sensitive information. Although JetBrains has invalidated all access tokens used by the JetBrains Cadence plugin in PyCharm, the company admits that the server should have been patched earlier as part of its vulnerability management efforts.
In response to this breach, JetBrains has urged users to conduct a thorough review of connected systems for any suspicious activities, especially in AWS accounts, S3 buckets, and other environments accessible with compromised credentials. Additionally, users should audit source code repositories for unauthorized changes, given the increased risk of targeted phishing and social engineering attacks resulting from the exposure of personal data. The affected server has been taken offline to prevent further exploitation.

