<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb" -->

---
title: JetBrains breached its own Cadence service after failing...
description: JetBrains disclosed a breach of its Cadence cloud execution service, which integrates with PyCharm, after failing to patch a critical TeamCity vulnerability...
canonical: https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: JetBrains breached its own Cadence service after failing to patch a TeamCity vulnerability it told customers to fix | daily.dev
og:description: JetBrains disclosed a breach of its Cadence cloud execution service, which integrates with PyCharm, after failing to patch a critical TeamCity vulnerability...
og:url: https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb
og:image: https://api.daily.dev/og/posts/NUgl9E5qb.png
og:image:alt: JetBrains breached its own Cadence service after failing to patch a TeamCity vulnerability it told customers to fix
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# JetBrains breached its own Cadence service after failing to patch a TeamCity vulnerability it told customers to fix

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

JetBrains disclosed a breach of its Cadence cloud execution service, which integrates with PyCharm, after failing to patch a critical TeamCity vulnerability (CVE-2026-63077) on its own Cadence server despite telling customers to fix it. Attackers exploited the unpatched flaw between August 8 and August 24, 2026, exposing usernames, emails, IPs, timestamps, and a 2024 backup containing AWS IAM credentials belonging to customers and employees. Attackers used those IAM credentials to reach S3 buckets, and source code synced from PyCharm during the breach window may have been accessed. JetBrains took the server offline, invalidated Cadence plugin tokens, and is urging customers to rotate credentials across AWS, Azure, GCP, GitHub, GitLab, Bitbucket, npm, PyPI, Docker registries, Slack, SSH keys, and signing certificates. Packages published through Cadence during the window should be treated as potentially compromised.

## Content

JetBrains disclosed a security incident affecting Cadence, its cloud execution service integrated with PyCharm. The company failed to patch a critical TeamCity vulnerability (CVE-2026-63077) on the Cadence server itself, despite urging customers to apply the fix. Attackers exploited that gap between August 8 and August 24, 2026.

The breach exposed a wide range of data: usernames, real names, email addresses, IP addresses, and timestamps. A 2024 Cadence server backup was also accessed, which contained credentials and AWS IAM users and secrets belonging to both customers and JetBrains employees. Attackers reached S3 buckets through those compromised IAM credentials. Source code synced from PyCharm to Cadence during the affected period may have been accessed as well.

JetBrains has taken the affected server offline and invalidated all Cadence plugin tokens. The company is advising users to rotate credentials across a broad surface area: AWS, Azure, GCP, GitHub, GitLab, Bitbucket, npm, PyPI, Docker registries, Slack, SSH keys, and signing certificates. Any packages or artifacts published through Cadence during the breach window should be treated as potentially compromised, given the supply chain risk from exposed publishing credentials.

All Cadence executions and outputs from August 8 through August 24 should be treated as untrusted until credentials are rotated and access logs reviewed.

## Questions this post answers

### What happened in the JetBrains Cadence security breach?

Attackers exploited an unpatched critical TeamCity vulnerability, CVE-2026-63077, on JetBrains' own Cadence server between August 8 and August 24, 2026, despite JetBrains having told customers to patch it. The breach exposed usernames, emails, IP addresses, timestamps, and a 2024 backup containing AWS IAM credentials belonging to customers and employees, which attackers used to access S3 buckets.

_Teams tracking supply chain incidents affecting their CI/CD toolchain follow breach disclosures like this on daily.dev._

### What should I rotate after the JetBrains Cadence breach?

JetBrains advises rotating credentials across AWS, Azure, GCP, GitHub, GitLab, Bitbucket, npm, PyPI, Docker registries, Slack, SSH keys, and signing certificates. All Cadence executions and outputs between August 8 and August 24, 2026 should be treated as untrusted until credentials are rotated and access logs are reviewed, since publishing credentials may have been exposed.

_Developers responding to credential rotation advisories can stay ahead of similar incidents via daily.dev._

### Is source code synced to JetBrains Cadence from PyCharm at risk after the breach?

Yes, source code synced from PyCharm to Cadence during the August 8 to August 24, 2026 breach window may have been accessed by attackers, since the compromised server handled that synced code alongside exposed AWS IAM credentials and a 2024 backup.

_Developers weighing the risk of cloud-synced IDE features can weigh trade-offs like this on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#devtools](https://daily.dev/tags/devtools), [#cicd](https://daily.dev/tags/cicd), [#jetbrains](https://daily.dev/tags/jetbrains)

[View this post on daily.dev](https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"JetBrains breached its own Cadence service after failing to patch a TeamCity vulnerability it told customers to fix","url":"https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb"},"datePublished":"2026-08-28T20:57:10.391Z","dateModified":"2026-08-28T20:57:49.469Z","description":"JetBrains disclosed a breach of its Cadence cloud execution service, which integrates with PyCharm, after failing to patch a critical TeamCity vulnerability...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6e0d0505196e879c1fc8e031985437d5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6e0d0505196e879c1fc8e031985437d5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,devtools,cicd,jetbrains","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"JetBrains breached its own Cadence service after failing to patch a TeamCity vulnerability it told customers to fix"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/jetbrains-breached-its-own-cadence-service-after-failing-to-patch-a-teamcity-vulnerability-it-told-c-nugl9e5qb#faq","mainEntity":[{"@type":"Question","name":"What happened in the JetBrains Cadence security breach?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploited an unpatched critical TeamCity vulnerability, CVE-2026-63077, on JetBrains' own Cadence server between August 8 and August 24, 2026, despite JetBrains having told customers to patch it. The breach exposed usernames, emails, IP addresses, timestamps, and a 2024 backup containing AWS IAM credentials belonging to customers and employees, which attackers used to access S3 buckets. Teams tracking supply chain incidents affecting their CI/CD toolchain follow breach disclosures like this on daily.dev."}},{"@type":"Question","name":"What should I rotate after the JetBrains Cadence breach?","acceptedAnswer":{"@type":"Answer","text":"JetBrains advises rotating credentials across AWS, Azure, GCP, GitHub, GitLab, Bitbucket, npm, PyPI, Docker registries, Slack, SSH keys, and signing certificates. All Cadence executions and outputs between August 8 and August 24, 2026 should be treated as untrusted until credentials are rotated and access logs are reviewed, since publishing credentials may have been exposed. Developers responding to credential rotation advisories can stay ahead of similar incidents via daily.dev."}},{"@type":"Question","name":"Is source code synced to JetBrains Cadence from PyCharm at risk after the breach?","acceptedAnswer":{"@type":"Answer","text":"Yes, source code synced from PyCharm to Cadence during the August 8 to August 24, 2026 breach window may have been accessed by attackers, since the compromised server handled that synced code alongside exposed AWS IAM credentials and a 2024 backup. Developers weighing the risk of cloud-synced IDE features can weigh trade-offs like this on daily.dev."}}]}
```

