TechNewsReel
Live

JetBrains Cadence Breached After Company Failed to Patch Own Critical Flaw

Attackers exploited a known TeamCity RCE vulnerability to access AWS credentials and customer data from the hosted service.

TechNewsReel Newsroom · September 5, 2026

JetBrains has confirmed a security breach of its Cadence cloud service after threat actors exploited a critical vulnerability in the company's own infrastructure. The incident underscores a significant security lapse, as the vulnerability used in the attack had already been patched and disclosed by JetBrains to the public.

The breach was made possible by the exploitation of CVE-2026-63077, an unauthenticated remote code execution (RCE) vulnerability in JetBrains TeamCity with a critical CVSS score of 9.8. According to JetBrains, attackers maintained access to the server from August 8 to August 24, 2026. The company officially acknowledged the investigation on August 28, 2026. During the intrusion, attackers accessed a full 2024 backup of the Cadence server, AWS IAM user credentials, files stored in JetBrains S3 buckets, and personal user data, including names, emails, and IP addresses.

A Failure of Internal Hygiene

JetBrains Cadence is a hosted service integrated with PyCharm that utilizes TeamCity for the orchestration of cloud compute resources. The irony of the breach lies in the timeline of the vulnerability: JetBrains had released the patch for CVE-2026-63077 in July 2026 and had actively warned the broader community to update their systems to prevent server takeovers. However, the company failed to apply that same patch to the internal TeamCity server powering the Cadence service, leaving a critical blind spot that attackers leveraged.

Industry Implications

This incident highlights a critical failure in security hygiene, specifically the gap between a vendor's public security guidance and its internal practices. When a security-focused software provider fails to implement its own disclosed fixes, it undermines trust in the product's overall security posture. Furthermore, the extraction of high-value AWS credentials creates a significant downstream risk, as these keys can potentially be used to compromise customer environments linked to the service.

Next Steps for Users

JetBrains has urged all Cadence users to take immediate action to secure their environments. The company stated that "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions." Users are advised to audit their AWS IAM logs for any unauthorized activity stemming from the leaked credentials while JetBrains continues to harden its internal orchestration infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.