• Sources: primary, HN submission
  • Summary: JetBrains states that the Cadence server at api.cadence.jetbrains.com was exploited through CVE-2026-63077, the critical unauthenticated TeamCity command-execution flaw JetBrains had already disclosed, and that the server was not patched as part of its own response. The stated exposure period runs 2026-08-08 to 2026-08-24, exploitation was found on 2026-08-23, and the server was taken offline on 2026-08-24. JetBrains states the confirmed impact covers usernames, real names, email addresses, last-login timestamps and last-accessed IP addresses, a full 2024 server backup, multiple AWS IAM users and their credentials, files in JetBrains S3 buckets, and possible access to source code synchronized from PyCharm projects. The affected TeamCity version range is not stated here, because the post gives it only by link to a separate JetBrains advisory that this run did not fetch.
  • Why it matters: Anyone who used Cadence has to revoke and rotate every credential the service could reach, covering cloud, source control, package registry, container registry, signing keys and SSH keys, and treat execution inputs and outputs as untrusted.
  • Follow-up: Track a full incident analysis from JetBrains, and check logs against the six exploitation IP addresses JetBrains published as indicators of compromise.

send feedback on this story