JetBrains is urging Cadence users to rotate all credentials after threat actors exploited a critical TeamCity vulnerability to access sensitive user data and cloud infrastructure backups.
Key Points
- Threat actors exploited CVE-2026-63077, a critical deserialization vulnerability in TeamCity, to breach the Cadence cloud computing service.
- The intrusion occurred between August 8 and August 24, 2026, leading to the permanent shutdown of the affected server.
- Compromised data includes user emails, project source code, AWS IAM credentials, and a full 2024 server backup.
- JetBrains has invalidated all Cadence plugin access tokens and advises users to audit connected systems for unauthorized activity.
- CISA added the exploited vulnerability to its Known Exploited Vulnerabilities catalog on August 5, 2026.