JetBrains Cadence Breach: Exploitation of Unpatched TeamCity CVE-2026-63077

JetBrains Cadence Breach: Exploitation of Unpatched TeamCity CVE-2026-63077

First seen 6 Sep 2026, 08:03 UTC ThehackernewsRescanawww.rapid7.comthenewstack.io 72.8

Article Content

Browse articles
ThreatCluster

Between August 8 and August 24, 2026, attackers exploited CVE-2026-63077, a critical vulnerability in JetBrains TeamCity, to breach the JetBrains Cadence cloud compute service. The attackers accessed sensitive data, including usernames, email addresses, and AWS IAM credentials, along with project source code and configuration files from a 2024 server backup. JetBrains discovered the breach on August 23, 2026, and took the affected server offline the next day. The vulnerability, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary commands on the TeamCity server. JetBrains had previously disclosed the vulnerability on July 27, 2026, and it was added to the CISA Known Exploited Vulnerabilities catalog on August 5, 2026. Users are advised to rotate all credentials and treat any data from the compromised environment as untrusted. The full scope of the breach, including potential access to customer data, is still being assessed.

Key Points: • Attackers exploited CVE-2026-63077 to breach JetBrains Cadence. • Sensitive data, including AWS IAM credentials and source code, was exfiltrated. • JetBrains failed to patch their own vulnerable TeamCity server before the attack.

Ask AI about this cluster

Timeline

2026-07-27
CVE-2026-63077 published
JetBrains disclosed a critical vulnerability in TeamCity On-Premises allowing remote code execution.
Rapid7
2026-08-05
CVE-2026-63077 added to CISA KEV
CISA listed CVE-2026-63077 in its Known Exploited Vulnerabilities catalog due to active exploitation.
Rapid7
2026-08-08
Attackers begin exploiting the vulnerability
Malicious activity started on the JetBrains Cadence server, leading to unauthorized access.
The Hacker News
2026-08-23
Breach discovered by JetBrains
JetBrains identified the exploitation of the Cadence environment and took the affected server offline.
Rescana
2026-08-24
Affected server taken offline
JetBrains took the compromised TeamCity server offline to mitigate further risks.
The New Stack