JetBrains Failed to Patch Its Own TeamCity Server and Its Cadence Cloud Coding Service Leaked Customer Source Code and Cloud Credentials
JetBrains Blog (corroborated by The New Stack, 2026-08-28)·high signal
JetBrains disclosed that attackers exploited CVE-2026-63077, the critical unauthenticated RCE flaw in TeamCity On-Premises that JetBrains itself published on July 27, against an unpatched JetBrains-run server, reaching the Cadence cloud service. Because the PyCharm plugin syncs project files to Cadence before running them, customer source code, config files and any embedded secrets may have been exposed, along with usernames, real names, emails, last-login timestamps and last-accessed IPs. JetBrains is telling Cadence users to treat all prior executions and outputs as untrusted and to rotate AWS, Azure, GCP, GitHub, GitLab, Bitbucket, npm, Maven, NuGet, PyPI, Docker Hub, ECR, GCR and ACR credentials.