DevOps / SRE / Platform · 28.08.2026, 21:02 UTC
JetBrains told everyone to patch. It didn’t patch itself.
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| CVE | ↗ |
| Kategorie | DevOps / SRE / Platform |
| Quelle | The New Stack ↗ |
| Veröffentlicht | 28.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-63077. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
JetBrains is urging users of its Cadence cloud development service to rotate credentials and treat previous executions and their outputs as untrusted after attackers exploited a critical TeamCity vulnerability on a server the company failed to patch.
The irony is hard to miss. JetBrains disclosed CVE-2026-63077, a critical vulnerability in TeamCity On-Premises, on July 27. The flaw allows an unauthenticated attacker with HTTP or HTTPS access to a vulnerable TeamCity server to execute arbitrary operating system commands with the privileges of the TeamCity server process.
By August 7, the company announced that attackers were already exploiting unpatched TeamCity servers.
But one vulnerable server was still exposed: JetBrains’ own.
“The server should have been patched as part of our response to the vulnerability, but it was not,” JetBrains acknowledged in its disclosure of the Cadence incident.
“The server should have been patched as part of our response to the vulnerability, but it was not,”
Cadence’s unpatched TeamCity server
Attackers targeted api.cadence.jetbrains.com, which is the server behind Cadence, JetBrains’ cloud compute service for PyCharm. JetBrains found out about the attack on August 23 and took the server offline the next day. Their investigation shows that malicious activity started on August 8, so the affected period is from August 8 to August 24.
Cadence integrates with PyCharm via an optional plugin, giving developers the ability to run projects on cloud compute resources. TeamCity sat behind the service, orchestrating those workloads.
That …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info Cybersecurity Researchers Uncover Flaw in Google AI Coding Tool
- info LM Studio built a judge for AI commands. Then the judge started agreeing with the defendant.
- info Alibaba just released Qwen3.8-Flash: “An early preview of the architecture in Qwen4”
- info Certificate Renewal Is a Deployment Workflow, Not a Cron Job