JetBrains urges Cadence users to rotate credentials after TeamCity breach

This digest was compiled by AI from multiple sources — links to the originals are below.
JetBrains urged Cadence users to immediately revoke and rotate all credentials following a security breach last month. Unidentified attackers exploited a critical TeamCity vulnerability, CVE-2026-63077, to access the Cadence server. The company said any credentials stored in Cadence or contained in a compromised 2024 backup should be considered compromised.
Key Facts
- JetBrains disclosed the breach on August 23, 2026, after detecting exploitation of CVE-2026-63077 in its Cadence environment.
- The vulnerability CVE-2026-63077 has a CVSS score of 9.8 and allows unauthenticated remote code execution on TeamCity servers.
- The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on August 5, 2026.
- Attackers accessed a Cadence server backup from 2024 containing email addresses, project source code, and credentials of current users.
Breach Discovery
JetBrains discovered the exploitation on August 23, 2026, and subsequently notified affected Cadence users. The attack leveraged CVE-2026-63077, a deserialization vulnerability in TeamCity with a CVSS score of 9.8. The flaw permits an unauthenticated attacker to bypass authentication and execute arbitrary operating system commands with TeamCity server process privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 5, 2026, indicating active exploitation in the wild.
Compromised Data
JetBrains confirmed that threat actors accessed a Cadence server backup from 2024. The backup contained data associated with current Cadence users, including email addresses, project source code, and credentials. Daniel Gallo, Solutions Engineering Lead at JetBrains, stated that the findings did not identify any additional affected users beyond those previously contacted. As a precaution, JetBrains is treating all data stored in the affected storage as potentially exposed.
User Guidance
JetBrains instructed Cadence users to immediately revoke or rotate all credentials and secrets used to run their Cadence executions. Users should treat all executions, including their inputs and outputs in Cadence projects, as potentially untrusted. Any credentials or secrets stored in Cadence, contained in the compromised backup, or made available to executions on the affected server should be considered compromised.