Attackers Exploited TeamCity CVE-2026-63077 (CVSS 9.8) to Breach JetBrains Cadence; Fixes Available in TeamCity On-Premises 2025.11.7 and 2026.1.3
Unknown attackers exploited critical TeamCity vulnerability CVE-2026-63077 (CVSS 9.8), added to CISA's KEV catalog on August 5, 2026, to breach JetBrains' Cadence service between August 8-24, 2026, accessing user personal data, a 2024 server backup, and AWS…
JetBrains disclosed that unknown threat actors exploited CVE-2026-63077 (CVSS 9.8), a critical unauthenticated vulnerability in TeamCity, to breach its Cadence cloud computing service, with the intrusion running August 8-24, 2026. The Hacker News characterizes the flaw as an unauthenticated deserialization vulnerability, while JetBrains' advisory describes it as an authentication bypass via the TeamCity agent polling protocol that allows arbitrary operating system command execution with the privileges of the server process; both reports agree all TeamCity On-Premises versions are affected, and JetBrains' advisory notes an attacker with HTTP(S) access can exploit it. Confirmed access in the Cadence breach includes personal data (usernames, names, emails, login timestamps, and IP addresses), a full 2024 Cadence server backup containing credentials and configuration, multiple AWS IAM users and secrets, files in JetBrains S3 buckets, and possibly PyCharm-synchronized source code. The compromised api.cadence.jetbrains.com server has been taken offline and all Cadence plugin access tokens invalidated, with six attacker IPs shared as IOCs. JetBrains urges users to immediately revoke or rotate all credentials used with Cadence and treat all executions, inputs, and outputs as potentially untrusted. Fixes are available in TeamCity On-Premises 2025.11.7 and 2026.1.3, or via a security patch plugin for TeamCity 2017.1+; TeamCity Cloud was already mitigated. JetBrains stated there was no evidence of active exploitation at the time of its fix disclosure, though The Hacker News reports the Cadence breach as confirmed exploitation of this CVE. Potential impacts of a successful compromise include exposure of stored credentials, altered server state, and corrupted CI/CD build artifacts.
- CVE-2026-63077 is a critical TeamCity vulnerability (CVSS 9.8) affecting all TeamCity On-Premises versions; it was added to CISA's KEV catalog on August 5, 2026.
- Sources describe the flaw differently: The Hacker News calls it an unauthenticated deserialization vulnerability, while JetBrains' advisory describes an authentication bypass via the TeamCity agent polling protocol enabling unauthenticated…
- Attackers exploited the flaw to breach JetBrains Cadence between August 8 and August 24, 2026.
- Accessed data includes usernames, names, emails, login timestamps, and IP addresses; a full 2024 Cadence server backup containing credentials and configuration; multiple AWS IAM users and secrets; files in JetBrains S3 buckets; and…
- The compromised api.cadence.jetbrains.com server was taken offline and all Cadence plugin access tokens were invalidated; six attacker IPs were shared as IOCs.
- JetBrains urges users to immediately revoke or rotate all credentials used with Cadence and treat all executions, inputs, and outputs as potentially untrusted.
- Remediation: update TeamCity On-Premises to 2025.11.7 or 2026.1.3, or install the security patch plugin for TeamCity 2017.1+; TeamCity Cloud is already mitigated.
- JetBrains stated there was no evidence of active exploitation at disclosure time (per the web-discovery report), while The Hacker News reports the Cadence breach as confirmed exploitation of CVE-2026-63077.
Coverage timelineoldest first · each row is one article
- · 10d agoAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News· 80
Unknown attackers exploited critical TeamCity flaw CVE-2026-63077 to breach JetBrains Cadence, stealing a 2024 backup, user data, and AWS credentials; rotation urged.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-63077 | Unauthenticated Deserialization RCE in JetBrains TeamCity On-Premises CVE-2026-63077 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in JetBrains TeamCity, caused by deserialization of untrusted data (CWE-502) in the agent polling protocol. An attacker with network access to the TeamCity server, but no credentials of any kind, can send maliciously crafted serialized input to the agent polling endpoint and execute arbitrary code on the server. Successful exploitation yields full server takeover, exposing source code, build logs, stored secrets and credentials, and providing a pivot point into build agents and connected infrastructure; related headlines describe a real breach in which AWS credentials were extracted from an unpatched TeamCity instance. Organizations running TeamCity On-Premises in versions prior to the fixes (2025.11.7 or 2026.1.3, depending on branch) are affected, while the JetBrains-hosted cloud service is not indicated as impacted. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-05, EPSS is 86.5% (100th percentile), and no public PoC is known, meaning defenders cannot rely on public scanners alone and should assume sophisticated attackers are targeting exposed servers. Do: Upgrade immediately to TeamCity 2025.11.7 or 2026.1.3, whichever branch you run; because the flaw is pre-authentication, also hunt for signs of compromise (unexpected builds or agents, new or modified admin users, altered build configurations, and leaked stored credentials/secrets) per vendor guidance, and restrict internet exposure of the TeamCity server until patched. Federal agencies must apply vendor mitigations or discontinue use per CISA BOD 26-04 and the KEV required action, including the Forensics Triage Requirements. | 9.8 | 87% | KEV |
| largetens of thousands of internet-exposed TeamCity on-premises servers (order of magnitude 10k-100k); total on-premises installs likely higher |