SECURITY Signal 134
JetBrains Cadence service compromised through CVE-2026-63077, exposing customer credentials and personal data
JetBrains confirmed that its Cadence cloud-execution service was accessed without authorization after a critical TeamCity vulnerability (CVE-2026-63077) was exploited.
The breach means any secrets, tokens, or code used in Cadence runs may have been stolen, requiring immediate rotation. It also shows that services built on vulnerable CI/CD components can expose downstream cloud resources, so teams must audit dependencies and treat past Cadence executions as untrusted.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Unauthorized access to Cadence was achieved by exploiting CVE-2026-63077 in the underlying TeamCity orchestrator.
Customer data, including usernames, real names, email addresses, login timestamps, and IAM credentials, was extracted and a 2024 backup was also compromised.
JetBrains advises all Cadence users to revoke/rotate credentials, treat prior executions as untrusted, and review cloud resources for suspicious activity.
THE CLUSTER
↗