JetBrains warns users to revoke credentials after attackers exploited a critical TeamCity vulnerability (CVE‑2026‑63077) to access Cadence cloud data, including backups and user information.
JetBrains has issued an urgent advisory urging all Cadence users to revoke their credentials after a breach exposed cloud data and AWS keys. Attackers leveraged an unpatched critical vulnerability in TeamCity (CVE‑2026‑63077) to infiltrate the CI/CD platform and extract sensitive information from JetBrains’ Cadence service.
How the breach unfolded
The exploitation began when threat actors accessed a TeamCity server that had not applied the security patch released for CVE‑2026‑63077. By gaining administrative control of the CI environment, the attackers were able to locate and download Cadence configuration files, backup archives, and associated AWS access keys stored for automated deployments.
Once the AWS keys were obtained, the intruders could query the underlying S3 buckets that host Cadence backups, effectively pulling user data, project metadata, and potentially proprietary code.
Impact on Cadence users
JetBrains confirmed that the breach exposed:
- Cadence user account details, including email addresses and usernames
- Project metadata and configuration files stored in Cadence
- Encrypted backup snapshots held in AWS S3
- AWS access keys that could be used to access other JetBrains cloud services
The company has not observed any evidence of malicious use of the stolen AWS keys yet, but it warns that the credentials could be repurposed for further attacks on connected infrastructure.
JetBrains’ response and recommendations
JetBrains has taken the following steps:
- Issued a security bulletin and patched the vulnerable TeamCity component
- Forced password resets for all Cadence accounts
- Revoked all previously issued AWS keys and generated new ones
- Provided a detailed remediation guide for affected customers
Customers are advised to immediately revoke any existing Cadence tokens, rotate AWS credentials, and review access logs for suspicious activity. JetBrains also recommends enabling multi‑factor authentication on all accounts and applying security patches promptly.
“This incident underscores the critical importance of timely patch management across the software supply chain,” said a JetBrains security spokesperson.
For a full breakdown of the vulnerability and mitigation steps, see the Cyber Ink Times coverage of the breach.