Security Incident Affecting JetBrains Cadence - The JetBrains Blog
Blog post from JetBrains
JetBrains reported that its Cadence cloud-compute service for PyCharm was compromised through CVE-2026-63077, a critical TeamCity vulnerability that enabled unauthenticated remote command execution on the affected server, api.cadence.jetbrains.com. The intrusion occurred between August 8 and August 24, 2026, was discovered on August 23, and led JetBrains to take the server offline while it investigates. Attackers accessed and extracted user data including names, usernames, email addresses, login timestamps, and IP addresses; compromised a 2024 server backup; accessed JetBrains AWS resources and S3 files; and may have obtained synchronized PyCharm project code and credentials used in Cadence executions. JetBrains has invalidated Cadence plugin access tokens, contacted affected users, and acknowledged that the server should have been patched. Users are urged to immediately revoke and rotate all potentially exposed credentials, inspect repositories, cloud accounts, storage, and connected services for suspicious activity, and consider Cadence execution data, uploaded files, secrets, and outputs untrusted.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.