<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw" -->

---
title: Security Incident Affecting JetBrains Cadence | daily.dev
description: JetBrains disclosed a security incident affecting Cadence, its cloud execution service integrated with PyCharm. Attackers exploited a critical TeamCity...
canonical: https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Security Incident Affecting JetBrains Cadence | daily.dev
og:description: JetBrains disclosed a security incident affecting Cadence, its cloud execution service integrated with PyCharm. Attackers exploited a critical TeamCity...
og:url: https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw
og:image: https://api.daily.dev/og/posts/CclNcNhkW.png
og:image:alt: Security Incident Affecting JetBrains Cadence
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Incident Affecting JetBrains Cadence

**[JetBrains](https://daily.dev/sources/jetbrains)** · 6 min read · 2 upvotes · 1 comments

## Summary

JetBrains disclosed a security incident affecting Cadence, its cloud execution service integrated with PyCharm. Attackers exploited a critical TeamCity vulnerability (CVE-2026-63077) that had not been patched on the Cadence server, gaining unauthorized access between August 8 and August 24, 2026. Exposed data includes usernames, real names, emails, timestamps, IPs, a 2024 backup containing credentials, and AWS IAM users/secrets belonging to both customers and JetBrains employees. Source code synced from PyCharm to Cadence may also have been accessed. JetBrains took the affected server offline, invalidated Cadence plugin tokens, and urges all users to rotate credentials, review cloud/source-control/package-registry access, and treat all Cadence executions as untrusted.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026>

## Questions this post answers

### What caused the JetBrains Cadence security breach in August 2026?

Attackers exploited CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, which Cadence used to orchestrate workloads. The Cadence server should have been patched against this vulnerability but was not, allowing exploitation from August 8, 2026, until it was discovered on August 23 and taken offline on August 24, 2026.

_Teams relying on TeamCity or Cadence can track vulnerability disclosures like this one on daily.dev to patch before exposure._

### What data was exposed in the JetBrains Cadence breach?

Confirmed exposed data includes usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses, plus a full 2024 backup of the Cadence server containing credentials, configuration, artifacts, and logs. Attackers also compromised AWS IAM users and secrets, including ones belonging to JetBrains employees, and may have accessed source code synced from PyCharm projects.

_Developers assessing blast radius after a supply-chain breach can follow incident updates like this on daily.dev._

### What should I do if I used JetBrains Cadence with PyCharm?

Immediately revoke and rotate all credentials and secrets used in Cadence executions, including cloud (AWS, Azure, GCP), source control (GitHub, GitLab, Bitbucket), package registry, container registry, and API/SSH keys. Review connected AWS accounts, S3 buckets, and repositories for unauthorized activity, and treat all Cadence execution inputs and outputs as untrusted, since the affected period ran from August 8 to August 24, 2026.

_Anyone triaging credential rotation after a breach can find similar incident response guidance on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@taiwofrancis** · 1 upvotes

> This is the kind of incident that reminds you that one unpatched server can turn into a much bigger problem really quickly.

## Similar posts on daily.dev

- [High-Severity Security Issue Affecting TeamCity On-Premises \(CVE-2026-44413\) – Update to 2026.1 Now](https://daily.dev/posts/high-severity-security-issue-affecting-teamcity-on-premises-cve-2026-44413-update-to-2026-1-now-dryw37woz) · JetBrains · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#devtools](https://daily.dev/tags/devtools), [#cicd](https://daily.dev/tags/cicd)

[View this post on daily.dev](https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Security Incident Affecting JetBrains Cadence","url":"https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw"},"datePublished":"2026-08-28T10:40:20.901Z","dateModified":"2026-08-28T20:57:34.714Z","description":"JetBrains disclosed a security incident affecting Cadence, its cloud execution service integrated with PyCharm. Attackers exploited a critical TeamCity...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fe4a7b56309049bd5a17f2d9cd0530cd?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fe4a7b56309049bd5a17f2d9cd0530cd?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"JetBrains","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"JetBrains","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/53ecf0c676f34b3896ee109609d91efa","url":"https://daily.dev/sources/jetbrains"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"cyber,devtools,cicd","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"JetBrains","item":"https://daily.dev/sources/jetbrains"},{"@type":"ListItem","position":3,"name":"Security Incident Affecting JetBrains Cadence"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw","comment":[{"@type":"Comment","text":"This is the kind of incident that reminds you that one unpatched server can turn into a much bigger problem really quickly.","datePublished":"2026-08-28T12:10:47.172Z","url":"https://daily.dev/posts/CclNcNhkW#c-suS4ikMJr","author":{"@type":"Person","name":"Taiwo Francis Oguntade","url":"https://daily.dev/taiwofrancis","image":"https://media.daily.dev/image/upload/s--px3_Pvo4--/f_auto/v1785515368/avatars/avatar_FStpm3ZejUD3qGlEeoOUS?_a=BAMAMicg0"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/security-incident-affecting-jetbrains-cadence-cclncnhkw#faq","mainEntity":[{"@type":"Question","name":"What caused the JetBrains Cadence security breach in August 2026?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploited CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, which Cadence used to orchestrate workloads. The Cadence server should have been patched against this vulnerability but was not, allowing exploitation from August 8, 2026, until it was discovered on August 23 and taken offline on August 24, 2026. Teams relying on TeamCity or Cadence can track vulnerability disclosures like this one on daily.dev to patch before exposure."}},{"@type":"Question","name":"What data was exposed in the JetBrains Cadence breach?","acceptedAnswer":{"@type":"Answer","text":"Confirmed exposed data includes usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses, plus a full 2024 backup of the Cadence server containing credentials, configuration, artifacts, and logs. Attackers also compromised AWS IAM users and secrets, including ones belonging to JetBrains employees, and may have accessed source code synced from PyCharm projects. Developers assessing blast radius after a supply-chain breach can follow incident updates like this on daily.dev."}},{"@type":"Question","name":"What should I do if I used JetBrains Cadence with PyCharm?","acceptedAnswer":{"@type":"Answer","text":"Immediately revoke and rotate all credentials and secrets used in Cadence executions, including cloud (AWS, Azure, GCP), source control (GitHub, GitLab, Bitbucket), package registry, container registry, and API/SSH keys. Review connected AWS accounts, S3 buckets, and repositories for unauthorized activity, and treat all Cadence execution inputs and outputs as untrusted, since the affected period ran from August 8 to August 24, 2026. Anyone triaging credential rotation after a breach can find similar incident response guidance on daily.dev."}}]}
```

