TeamCity Breach Reached JetBrains Cadence Backup

JetBrains said attackers used TeamCity CVE-2026-63077 to break into its own Cadence environment and reach a 2024 backup that held credentials and user data. The company says the incident was discovered in August and that the same affected user group it contacted earlier is still the scope of concern. The flaw let an unauthenticated attacker hit TeamCity’s agent-polling path and run commands on the server. Once inside Cadence, the attackers could get data stored there, data inside the backup, and secrets made available to executions, which is why JetBrains is treating current-user emails, source code, and cloud credentials as potentially exposed. For teams that use a job runner or CI/CD system to access cloud accounts, registries, or repositories, the exposure does not stop at the patched host. If execution secrets or backups sit on the same server, a server compromise can turn into downstream access even after the original bug is fixed.

Part of the PlainSec briefing for 2026-09-05

Editions

CVEs

Sources