Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthorized access. JetBrains discovered the activity on August 23 and took the server offline on August 24. The attackers accessed and exfiltrated personal data including usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses.
The attackers also accessed a 2024 Cadence server backup containing credentials, configuration, artifacts, logs, and other data. Credentials exposed through the backup included multiple AWS IAM users and associated secrets, which enabled access to files in S3 buckets belonging to JetBrains AWS accounts. Source code synchronized from PyCharm projects may also have been accessible. JetBrains stated on August 31 that it had no evidence that secrets or other data were extracted from the current Cadence environment, but credentials or secrets stored in Cadence, contained in the compromised backup, or otherwise available to Cadence executions should be considered compromised.