Executive Summary
Between August 8 and August 24, 2026, attackers exploited an unpatched critical vulnerability (CVE-2026-63077) in JetBrains TeamCity to breach the JetBrains Cadence cloud compute service. The attackers gained unauthorized access to the Cadence environment, extracting sensitive data including usernames, real names, email addresses, last-login timestamps, last accessed IP addresses, and multiple AWS IAM credentials. The breach also exposed project source code, configuration files, and secrets stored in a 2024 Cadence server backup, as well as files in S3 buckets within JetBrains AWS accounts. JetBrains discovered the exploitation on August 23, 2026, and took the affected server offline the following day. The incident highlights the critical risk posed by unpatched CI/CD infrastructure and the potential for supply chain compromise, credential theft, and lateral movement to cloud and development environments. All claims in this summary are directly supported by the official JetBrains disclosure (https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/), Rapid7 technical analysis (https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/), and sector reporting from The New Stack (https://thenewstack.io/jetbrains-told-everyone-to-patch-it-didnt-patch-itself/).
Technical Information
The breach of JetBrains Cadence was enabled by exploitation of CVE-2026-63077, a critical unauthenticated remote code execution (RCE) vulnerability in TeamCity On-Premises. This flaw, rated CVSS 9.8, allows attackers to execute arbitrary operating system commands as the TeamCity server process via the agent polling protocol. All TeamCity On-Premises versions prior to 2025.11.7 or 2026.1.3 are affected. The vulnerability was publicly disclosed and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026, indicating active exploitation in the wild (https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/).
Attackers gained initial access to the Cadence environment by exploiting the unpatched TeamCity server at api[.]cadence[.]jetbrains[.]com. Once inside, they accessed a full 2024 Cadence server backup, which contained multiple AWS IAM credentials, configuration files, and other secrets. The attackers also accessed files in S3 buckets within JetBrains AWS accounts, including those used by Cadence. The scope of customer bucket access remains undetermined.
Exfiltrated data included usernames, real names, email addresses, last-login timestamps, last accessed IP addresses, project source code, and secrets from the backup. These secrets encompassed cloud credentials, source control tokens, package/container registry credentials, Slack tokens, webhooks, API tokens, SSH/deployment keys, service account credentials, and signing keys/certificates. The attackers’ use of multiple IP addresses and targeting of cloud credentials is consistent with both criminal and advanced persistent threat (APT) activity, though no specific threat actor attribution has been made.
No specific malware or custom tools were identified in the attack. The compromise relied on direct exploitation of the TeamCity RCE vulnerability and subsequent use of legitimate credentials and cloud APIs for lateral movement and data access. This approach is consistent with recent trends in CI/CD pipeline attacks, where attackers leverage platform vulnerabilities and harvested credentials to move laterally and exfiltrate sensitive assets.
The incident underscores the high value of CI/CD and remote execution systems as targets, given their access to private repositories, dependencies, cloud storage, package registries, and deployment systems. Compromised credentials could allow attackers to publish malicious packages, leading to software supply chain attacks. Organizations using Cadence or TeamCity are advised to treat all outputs and credentials as untrusted, rotate all secrets, and audit for lateral movement.
Affected Versions & Timeline
All versions of TeamCity On-Premises prior to 2025.11.7 or 2026.1.3 are affected by CVE-2026-63077. The attack on JetBrains Cadence began on August 8, 2026, with malicious activity detected on the Cadence server (api[.]cadence[.]jetbrains[.]com). JetBrains discovered the exploitation on August 23, 2026, and took the server offline on August 24, 2026. On August 28, JetBrains confirmed exploitation of the vulnerability and, by August 31, confirmed that attackers had accessed a 2024 Cadence server backup. The investigation concluded on September 3, 2026, with confirmation of additional potential exposure involving cloud storage.
Threat Activity
The attackers exploited the TeamCity RCE vulnerability to gain initial access, then moved laterally by accessing a full server backup containing sensitive credentials and configuration files. They leveraged compromised AWS IAM credentials to access S3 buckets and potentially other cloud resources. The attackers exfiltrated personal data, source code, and secrets, increasing the risk of targeted phishing, social engineering, impersonation, and supply chain attacks. The use of multiple IP addresses and targeting of cloud credentials aligns with both financially motivated and state-sponsored threat actors, though no unique technical artifacts or threat actor signatures were identified.
The breach demonstrates a pattern of targeting CI/CD platforms for supply chain compromise, credential theft, and lateral movement. The lack of timely patching, even by the vendor, highlights the importance of rapid vulnerability management in environments with access to sensitive assets.
Mitigation & Workarounds
The following mitigation steps are prioritized by severity:
Critical: Immediately update all TeamCity On-Premises servers to version 2025.11.7 or 2026.1.3, or apply the official JetBrains security patch plugin. Restrict network access to TeamCity servers to trusted sources only.
Critical: Rotate and revoke all credentials and secrets used with Cadence, including AWS IAM credentials, source control tokens, package/container registry credentials, Slack tokens, webhooks, API tokens, SSH/deployment keys, service account credentials, and signing keys/certificates. Treat all executions and outputs from Cadence during the affected period as untrusted.
High: Audit all connected systems for unauthorized access, lateral movement, and unexpected changes. Review logs for signs of compromise, especially in cloud, source control, and deployment environments.
High: Notify all affected users and stakeholders of the breach, and provide guidance on credential rotation and incident response.
Medium: Implement network segmentation and access controls for CI/CD infrastructure. Regularly review and update security policies for credential storage and access.
Medium: Monitor for targeted phishing, social engineering, and impersonation attempts leveraging exposed data.
Low: Review and update incident response plans to address CI/CD and supply chain attack scenarios.
Indicators of Compromise
The following indicators are provided as a point-in-time reference and should be validated in your environment before enforcement. All indicators are defanged for safe publication.
Type | Indicator | Reported (date) | Source
|
IPv4 | 150[.]109[.]230[.]104 | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
IPv4 | 43[.]153[.]227[.]206 | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
IPv4 | 62[.]210[.]127[.]48 | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
IPv4 | 210[.]247[.]242[.]190 | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
IPv4 | 15[.]235[.]225[.]205 | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
IPv4 | 152[.]233[.]30[.]18 | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
Domain | api[.]cadence[.]jetbrains[.]com | 2026-09-03 | https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/ |
References
JetBrains Official Disclosure (September 3, 2026): https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/
Rapid7 Technical Analysis (July 29–August 7, 2026): https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/
The New Stack News Report (August 28, 2026): https://thenewstack.io/jetbrains-told-everyone-to-patch-it-didnt-patch-itself/
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor risks in their software supply chain and CI/CD environments. Our platform enables continuous visibility into vendor security posture, automated detection of exposed credentials and misconfigurations, and actionable insights for rapid incident response and remediation.
We are happy to answer questions at info@rescana.com.



