JetBrains Cadence Breached via Actively Exploited TeamCity Vulnerability, AWS Credentials Stolen
JetBrains is urging Cadence users to revoke and rotate all credentials after a security incident where attackers exploited a critical vulnerability, CVE-2026-63077 (CVSS score: 9.8), in TeamCity to breach its Cadence environments. The deserialization of untrusted data flaw allowed unauthenticated attackers to execute arbitrary commands and led to the extraction of AWS credentials and potential access to user data, including email addresses and project source code. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai