JetBrains has issued an urgent advisory for Cadence users following a significant security breach. Unidentified cyber actors exploited a critical vulnerability in TeamCity, leading to unauthorized access to Cadence’s environment. Users are strongly encouraged to revoke and rotate all credentials linked to their Cadence executions to mitigate potential risks.
Details of the Security Vulnerability
The breach was facilitated through the exploitation of a severe flaw identified as CVE-2026-63077, which carries a CVSS score of 9.8. This vulnerability enables unauthenticated attackers to bypass security checks and execute arbitrary commands on the TeamCity server. The flaw has been actively exploited, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) acknowledging it in their Known Exploited Vulnerabilities catalog as of August 5, 2026.
JetBrains discovered the compromise on August 23, 2026, and has since taken the affected Cadence server offline. The server was found to host potentially exposed credentials, necessitating urgent action from users to protect their data.
Extent of Data Compromise
The attackers accessed backups from 2024, which held sensitive information such as usernames, email addresses, and AWS credentials. This breach might have affected storage containing data linked to current users, including project source code. JetBrains’ Daniel Gallo emphasized the need to treat all stored data as potentially exposed, although the company has confirmed that no additional users were impacted beyond those previously notified.
In addition, the threat actors may have accessed source code synchronized from PyCharm projects to Cadence, posing a risk of inadvertent exposure of code, credentials, and configurations.
Recommended Actions for Users
JetBrains has invalidated all access tokens used to connect Cadence with PyCharm. Users are advised to audit their AWS accounts, source code repositories, and other systems for any unauthorized activity. This includes unexpected IP logins, access to cloud storage, and alterations in repository settings.
The security breach underscores the heightened risk of phishing and social engineering attempts using the exposed data. As a precaution, users should remain vigilant against unsolicited communications that might exploit this information.
Going forward, JetBrains is committed to addressing the vulnerabilities and enhancing their response protocols to prevent future incidents. Users are urged to stay informed and take necessary actions to secure their environments.
