JetBrains disclosed that unidentified attackers breached its Cadence cloud-service environment by exploiting CVE-2026-63077, a critical unauthenticated remote-code-execution flaw in TeamCity On-Premises. The intrusion, detected after activity from August 8 through August 24, potentially exposed a 2024 Cadence server backup and data reachable from the affected server, including Cadence user personal data, PyCharm-synchronized project source code, AWS IAM credentials, configuration, artifacts, logs, and files in Cadence-associated S3 buckets.
CVE-2026-63077 is an insecure-deserialization vulnerability in TeamCity server-to-build-agent communications that can execute commands under the TeamCity server process account. CISA has listed it as actively exploited and JetBrains fixed it in TeamCity On-Premises versions 2025.11.7 and 2026.1.3. JetBrains took the affected Cadence API server offline and invalidated Cadence plugin tokens; affected customers should rotate credentials, investigate connected systems, and treat Cadence executions and associated inputs and outputs as untrusted.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
JetBrains discovered the exploitation affecting its Cadence environment. The investigation found that the attackers had accessed a full Cadence server backup from 2024 and could potentially access storage containing current user data.
Unidentified attackers exploited CVE-2026-63077 to compromise JetBrains' Cadence cloud-service environment between August 8 and 24. The affected Cadence API server had not been patched during JetBrains' vulnerability-response process.
CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog after identifying active exploitation. The flaw enables unauthenticated remote command execution on vulnerable TeamCity On-Premises servers.
JetBrains reported that attackers accessed customer buckets through S3 buckets in its AWS environment after compromising Cadence-related credentials. The extent of customer-bucket access was not known.
JetBrains took api.cadence.jetbrains.com offline and invalidated all Cadence plugin access tokens. It directed affected users to rotate credentials, investigate connected systems, and treat Cadence executions and their inputs and outputs as untrusted.
JetBrains determined that attackers accessed or compromised multiple Cadence-related AWS IAM users and credentials, as well as files in Cadence-related S3 buckets. Potentially exposed data included Cadence user details, PyCharm-synchronized source code, configuration, artifacts, logs, and credentials.
JetBrains released fixes for the critical insecure-deserialization flaw in TeamCity On-Premises in versions 2025.11.7 and 2026.1.3, and provided a security plugin as a temporary mitigation for organizations unable to upgrade.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourceinfosec.pub
Open sourcethehackernews.com
Open sourcethreats.wiz.io
Open sourcecert.aikt.rs
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.