TechBriefe
Cloud

JetBrains Urges Cadence Users to Reset Credentials After TeamCity Exploit

James Thornton 05.09.2026

How Did the Breach Occur Despite Public Warnings?

JetBrains is advising users of its Cadence cloud development service to rotate credentials and treat past executions as untrusted after attackers exploited a critical vulnerability in TeamCity on an unpatched internal server. The flaw, identified as CVE-2026-63077, allowed unauthorized access despite JetBrains publicly disclosing the issue and urging customers to apply patches. The incident highlights a gap between the company’s security guidance and its own internal practices.

The vulnerability in TeamCity, a widely used continuous integration and deployment server, enables remote code execution if left unpatched. JetBrains released details about CVE-2026-63077 earlier this month, emphasizing the need for immediate updates across all installations. However, internal investigations revealed that one of JetBrains’ own servers running TeamCity remained unpatched, which attackers leveraged to compromise systems connected to the Cadence service. As a precaution, the company now recommends that Cadence users assume any prior job runs or artifacts may be tainted and should regenerate secrets used in workflows.

What Steps Should Cadence Users Take Now?

JetBrains’ security team confirmed that the exploited server was not running the latest version of TeamCity at the time of the attack, even though patches for CVE-2026-63077 had been available for several days. The oversight allowed threat actors to gain foothold access, potentially enabling them to inspect or manipulate build pipelines. While JetBrains states there is no evidence of data theft or customer impact beyond the exposed server, the incident raises questions about internal patch management protocols. The company has since isolated the affected system and begun a full forensic review.

Users are instructed to rotate all API keys, tokens, and credentials used within Cadence workflows, particularly those that may have been exposed during builds. JetBrains also advises reviewing build logs for anomalies and avoiding reuse of any artifacts generated before the patch was applied. The company has provided a script to help automate credential rotation and is offering extended support for affected teams. No service downtime has been reported, but trust in the platform’s security posture may require rebuilding.

What is CVE-2026-63077? CVE-2026-63077 is a critical remote code execution vulnerability in JetBrains TeamCity that allows attackers to execute arbitrary code on unpatched servers.

Frequently Asked Questions

Is my Cadence data compromised? JetBrains states there is no current evidence of customer data theft, but recommends treating prior executions as untrusted as a precaution.

How do I know if I need to act? All Cadence users should rotate credentials and validate recent build outputs, regardless of perceived exposure level.

Share:

More stories: