We are investigating a security incident affecting JetBrains Cadence. Cadence is a JetBrains-hosted service that integrates with PyCharm through an optional plugin, and lets you run your projects on cloud compute resources. Our investigation has confirmed unauthorized access to the service and the exposure of customer data associated with its use.
We have contacted affected users directly and have taken steps to contain the incident.
This post provides the latest information the incident, its potential impact, and the actions we recommend Cadence users take. We will update it as our investigation progresses and additional information becomes available.
Last updated: August 28, 2026, 11:50 CEST
Cadence is a JetBrains-hosted service integrated with PyCharm through an optional plugin, that lets you run your projects on cloud compute resources. Cadence uses JetBrains TeamCity to orchestrate this work. We recently disclosed CVE-2026-63077 , a critical vulnerability in TeamCity that can allow an unauthenticated attacker to execute arbitrary commands on a vulnerable server.
We have since confirmed the Cadence environment was vulnerable to CVE-2026-63077 and was exploited through this vulnerability.
Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions. They should also treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted.
We strongly recommend that Cadence users:
Cadence users can us to request an inventory of the credentials and secrets associated with their Cadence usage. This may help users identify which credentials need to be revoked or rotated, but the inventory should not be considered exhaustive.
We have collated a list of Indicators of Compromise (IoCs) below. These indicators are not exhaustive, and the absence of these indicators does not confirm that an account or system was unaffected:
We have confirmed that the following Cadence server was successfully exploited: api.cadence.jetbrains.com .
August 8, 2026, to August 24, 2026.
The Cadence server used TeamCity to orchestrate workloads and was vulnerable to CVE-2026-63077. Threat actors exploited the vulnerability and gained unauthorized access to the affected Cadence environments, with activity identified from August 8, 2026. We discovered the exploitation on August 23, 2026, and took the affected server offline on August 24, 2026, while we continued our investigation.
Our investigation is ongoing, but we have confirmed that the threat actors:
The likely consequences of the personal data exposure include an increased risk of targeted phishing, social engineering, impersonation, and other unsolicited or malicious communications using the affected names and email addresses.
As the threat actors gained access to the Cadence server, any credentials or secrets stored in Cadence, contained in the compromised backup, or made available to executions on the affected server should be considered compromised and must be revoked or rotated.
This includes but is not limited to:
We took the Cadence server offline on August 24, 2026, while we continue to investigate the incident. At present, we have confirmed that the incident is limited to data associated with the Cadence host mentioned above.
The server should have been patched as part of our response to the vulnerability, but it was not. We sincerely apologize for this failure and the impact it may have on you.
We have invalidated all access tokens used by the JetBrains Cadence plugin in PyCharm to connect to Cadence, and took the server offline on August 24, 2026.
We are also notifying the relevant authorities and taking the necessary steps to protect the data of Cadence users.
We will publish further findings and guidance here as our investigation progresses. We recommend checking this page frequently for the latest information. We will also affected users directly if we identify any important new information that may require action on their part.
For more information the underlying vulnerability, please see our original security advisory to TeamCity customers and users.
If you previously used Cadence and need assistance identifying which credentials may have been exposed or have any questions regarding this incident, the JetBrains Security team at [email protected] .
We recognize the seriousness of this incident and apologize again for the impact.
Thanks, we've got you!