Rescana
JetBrains Cadence Breach: Exploitation of Unpatched TeamCity CVE-2026-63077
Article Content
Between August 8 and August 24, 2026, attackers exploited CVE-2026-63077, a critical vulnerability in JetBrains TeamCity, to breach the JetBrains Cadence cloud compute service. The attackers accessed sensitive data, including usernames, email addresses, and AWS IAM credentials, along with project source code and configuration files from a 2024 server backup. JetBrains discovered the breach on August 23, 2026, and took the affected server offline the next day. The vulnerability, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary commands on the TeamCity server. JetBrains had previously disclosed the vulnerability on July 27, 2026, and it was added to the CISA Known Exploited Vulnerabilities catalog on August 5, 2026. Users are advised to rotate all credentials and treat any data from the compromised environment as untrusted. The full scope of the breach, including potential access to customer data, is still being assessed.
Key Points: • Attackers exploited CVE-2026-63077 to breach JetBrains Cadence. • Sensitive data, including AWS IAM credentials and source code, was exfiltrated. • JetBrains failed to patch their own vulnerable TeamCity server before the attack.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.