Attackers exploited CVE-2026-63077, a critical (CVSS 9.8) authentication-bypass and arbitrary-command-execution flaw affecting all JetBrains TeamCity On-Premises versions, to compromise an unpatched TeamCity server supporting JetBrains’ Cadence cloud development service. Activity at api.cadence.jetbrains.com ran from August 8 to August 24 and may have exposed a 2024 server backup, user data, source code, credentials, configurations, build artifacts, and logs. JetBrains confirmed compromise of several AWS IAM users and access to files in its AWS S3 buckets, while it continued investigating whether customer storage buckets were accessed.
Australian authorities and CISA had already warned of active exploitation and urged organizations to identify exposed TeamCity instances, apply JetBrains updates or its security patch plugin, and remove TeamCity interfaces from direct internet exposure where possible. Public exploit support has also advanced through Metasploit module exploit/multi/http/jetbrains_teamcity_rce_cve_2026_63077, including improved payload selection for Java/JSP, Windows, and Linux targets. Cadence users should rotate every credential and secret handled by the service, investigate connected environments for unauthorized activity and lateral movement, and treat executions and outputs generated during the exposure period as untrusted.

See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
GitHub automation added an enhancement for Metasploit's CVE-2026-63077 TeamCity RCE module to the project Kanban Todo board. The proposed changes improve target-specific payload selection and prefer HTTP-based payload fetching.
JetBrains took the affected Cadence TeamCity server offline, ending the assessed August 8–24 affected period. Attackers had obtained a complete 2024 server backup and accessed files in JetBrains AWS S3 buckets used by Cadence.
JetBrains discovered that attackers had exploited its unpatched Cadence TeamCity server. The company acknowledged the server should have been patched for CVE-2026-63077.
JetBrains assessed that malicious activity began on August 8 against an unpatched TeamCity server behind api.cadence.jetbrains.com, which orchestrated Cadence cloud-compute workloads.
JetBrains issued a follow-up advisory reporting active and attempted exploitation targeting unpatched TeamCity servers, and instructed customers to update to TeamCity 2025.11.7 or 2026.1.3 or install the security patch plugin immediately.
CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation, warning that such flaws present significant risks to the federal enterprise.
JetBrains disclosed CVE-2026-63077, a CVSS 9.8 flaw affecting all TeamCity On-Premises versions that lets unauthenticated HTTP(S) attackers bypass authentication and execute operating-system commands. JetBrains released patches during July and directed users to update or use its security patch plugin.
Two vulnerabilities affecting TeamCity On-Premises were reported as extensively exploited in 2024, including one that allowed remote unauthenticated attackers to completely compromise a server.
A critical TeamCity vulnerability disclosed in 2023 was targeted by Russian and North Korean nation-state actors.
The Australian Cyber Security Centre warned that threat actors were actively exploiting CVE-2026-63077 and that Australian organizations operating TeamCity On-Premises were at risk. It urged organizations to identify exposed instances, apply updates or the patch plugin, and reconsider internet exposure of TeamCity interfaces.
JetBrains advised Cadence users to rotate secrets and credentials used or stored in Cadence, treat affected-period executions as untrusted, and investigate connected source-control, cloud, and package environments for misuse or lateral movement.
JetBrains confirmed compromise of several AWS IAM users and associated credentials, while still determining whether customer storage buckets were accessed. It said Cadence user data, source code, credentials, configuration, artifacts, logs, and execution outputs may have been exposed or affected.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcegithub.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.