
Episode notes
JetBrains has disclosed that attackers breached Cadence — its PyCharm-integrated cloud compute service — through one of its own unpatched TeamCity servers, using a vulnerability in a JetBrains product that JetBrains had already patched and publicly warned about.
What Cadence is: a JetBrains-hosted service that integrates with PyCharm through an optional plugin and lets users run their projects on cloud compute resources. Cadence uses TeamCity to orchestrate that work.
The flaw: CVE-2026-63077 in TeamCity On-Premises, unauthenticated remote code execution via the agent polling protocol, allowing an attacker to bypass authentication checks and execute arbitrary operating system commands. CVSS v3.1 base score 9.8, as assigned by JetBrains in the CVE record. Fixed in 2025.11.7 and 2026.1.3.
Timeline. 27 July 2026: JetBrains publishes the advisory and fixed versions. 5 Aug: CISA adds it to the Known Exploited Vulnerabilities catalogue. 7 Aug: JetBrains publishes a second post warning of active exploitation in the wild. 8 Aug: attackers access JetBrains' own Cadence environment through an unpatched TeamCity server — twelve days after the patch shipped, and one day after JetBrains' own exploitation warning. 23 Aug: JetBrains discovers the exploitation. 24 Aug: the affected server is taken offline, closing the stated affected period of 8 to 24 August. 28 Aug: public disclosure; the investigation concluded on 3 September.
Not an orphaned server. The exploited host was the production API server for Cadence — a live, customer-facing service. JetBrains' explanation: "The server should have been patched as part of our response to the vulnerability, but it was not."
What was accessed: usernames, real names, email addresses, last login timestamps and last accessed IP addresses; a full 2024 backup of the Cadence server containing credentials, configuration, artifacts and logs; multiple AWS IAM users and secrets, including IAM users belonging to JetBrains employees; and files in S3 buckets within JetBrains AWS accounts. JetBrains states the attacker "may have accessed source code synchronized from PyCharm projects" — flagged as unconfirmed. In its 3 September update, JetBrains confirmed the actor obtained access that could have reached storage containing data associated with current Cadence users, including email addresses, project source code and credentials. No affected-user count has been published, and no threat actor has claimed the intrusion.
Remediation guidance, in JetBrains' words: "Revoke and rotate all credentials and secrets that may have been used to run Cadence executions." And: "Treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted."
Three things to take from it. First, treat your build system as production infrastructure — it holds deployment credentials and runs code automatically; put the console behind a VPN or IP allowlist. Second, inventory your long-lived secrets and give them an expiry: static AWS IAM keys work from anywhere, generate no login alert, and keep working until rotated — and a key frozen in a two-year-old backup has had two years to be forgotten. Third, patching is a delivery, not a decision. JetBrains decided to patch, announced it and warned the world, and the remediation still did not reach one production server. Close the ticket when you can produce a verified version number for every affected instance, not when the patch is approved.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: JetBrains Cadence security incident disclosure (28 August 2026, updated 3 September); JetBrains TeamCity advisory for CVE-2026-63077 (27 July 2026) and active-exploitation notice (7 August 2026); CISA KEV catalogue.
