JetBrains JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any JetBrains product.

RSS Feeds for JetBrains security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by JetBrains Sorted by Most Security Vulnerabilities since 2018

JetBrains Teamcity271 vulnerabilities

JetBrains Youtrack129 vulnerabilities

JetBrains Intellij Idea77 vulnerabilities

JetBrains Hub36 vulnerabilities

JetBrains Ktor22 vulnerabilities

JetBrains Pycharm11 vulnerabilities

JetBrains Toolbox10 vulnerabilities

JetBrains Webstorm9 vulnerabilities

JetBrains Goland8 vulnerabilities

JetBrains Rider7 vulnerabilities

JetBrains Kotlin7 vulnerabilities

JetBrains Phpstorm6 vulnerabilities

JetBrains Rubymine4 vulnerabilities

JetBrains Resharper2 vulnerabilities

JetBrains Clion2 vulnerabilities

JetBrains Mps2 vulnerabilities

JetBrains Junie1 vulnerability

JetBrains Rustrover1 vulnerability

JetBrains Dataspell1 vulnerability

JetBrains Datagrip1 vulnerability

JetBrains Aqua1 vulnerability

Known Exploited JetBrains Vulnerabilities

The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVE-2026-63077
August 5, 2026
JetBrains TeamCity Relative Path Traversal Vulnerability JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2024-27199 Exploit Probability: 100.0%
April 20, 2026
JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
CVE-2024-27198 Exploit Probability: 99.9%
March 7, 2024
JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-42793 Exploit Probability: 100.0%
October 4, 2023

Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 87 vulnerabilities in JetBrains with an average score of 6.8 out of ten. Last year, in 2025 JetBrains had 84 security vulnerabilities published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.75.




Year Vulnerabilities Average Score
2026 87 6.83
2025 84 6.07
2024 103 6.20
2023 54 6.54
2022 75 6.48
2021 88 6.66
2020 57 6.38
2019 57 8.28
2018 2 0.00

It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-75060 Aug 17, 2026
Unauthenticated code exec in JetBrains PyCharm <2026.2.1 via Jupyter MCP In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
Pycharm
CVE-2026-75059 Aug 17, 2026
JetBrains PyCharm Code Execution via Quick Documentation (Before 2026.2.1) In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Pycharm
CVE-2026-75058 Aug 17, 2026
IntelliJ IDEA Pre2026.2.1 xXE via Eclipse Settings Importer In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
Intellij Idea
CVE-2026-75057 Aug 17, 2026
IntelliJ IDEA <2026.1.5 - Git Credentials Logged in Plaintext In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
Intellij Idea
CVE-2026-75056 Aug 17, 2026
Remote Code Exec in IntelliJ IDEA <2026.2.1 via Markdown Export In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
Intellij Idea
CVE-2026-75055 Aug 17, 2026
IntelliJ IDEA <2026.2.1, Hadoop ResourceManager XXE Local File Read In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
Intellij Idea
CVE-2026-75054 Aug 17, 2026
IntelliJ IDEA <2026.2.1 sSRF via OpenAPI preview proxy In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
Intellij Idea
CVE-2026-75053 Aug 17, 2026
SRF in JetBrains IntelliJ IDEA < 2026.2.1 via DevKit Debug Listener In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
Intellij Idea
CVE-2026-75052 Aug 17, 2026
CVE-2026-75052: CMD exec via Markdown preview in IntelliJ IDEA < 2026.2.1 In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
Intellij Idea
CVE-2026-75051 Aug 17, 2026
YouTrack 2026.2.17917: Unauthorized Project Transfer Between Orgs In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
Youtrack
CVE-2026-75050 Aug 17, 2026
YouTrack DoS via crafted type params in <2026.1.13901 & 2026.2.17950 In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
Youtrack
CVE-2026-75049 Aug 17, 2026
YouTrack Auth Read Rstrctd Articles via Draft-Create EP (v1.13903/v2.17950) In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
Youtrack
CVE-2026-75048 Aug 17, 2026
JetBrains YouTrack <2026.2.18068 XSS via Code Label In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Youtrack
CVE-2026-75047 Aug 17, 2026
JetBrains YouTrack DoS via decompression bomb (pre-2026.2.18177) In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
Youtrack
CVE-2026-75046 Aug 17, 2026
YouTrack <=2026.2.18112: Auth User Enum via Search (CVE-2026-75046) In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
Youtrack
CVE-2026-75045 Aug 17, 2026
JetBrains YouTrack < 2025.3.156085, 2026.x: Unauth DB backup via draft sig In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Youtrack
CVE-2026-75044 Aug 17, 2026
JetBrains YouTrack 2026.2.18095: Auth Deletion via Mailbox Endpt In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
Youtrack
CVE-2026-68762 Aug 17, 2026
Ktor WebSocket Decompression DoS before 3.4.1 In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
Ktor
CVE-2026-63077 Jul 27, 2026
JetBrains TeamCity <2026.1.3 Remote Code Execution via Agent Polling In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Teamcity
CVE-2026-65907 Jul 23, 2026
TeamCity <2026.1.2 Git VCS CodeExec Vulnerability In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Teamcity
CVE-2026-65908 Jul 23, 2026
JetBrains PyCharm <2026.1.4, 2026.2 Arbitrary Exec via Malicious Python In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
Pycharm
CVE-2026-65906 Jul 23, 2026
TeamCity RCE via Kotlin DSL sandbox escape before 2026.1.2/2025.11.6 In JetBrains TeamCity before 2026.1.2, 2025.11.6 ode execution via Kotlin DSL sandbox escape was possible
Teamcity
CVE-2026-64815 Jul 23, 2026
IntelliJ IDEA UI Designer Form Files Code Injection <2026.2 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
Intellij Idea
CVE-2026-64814 Jul 23, 2026
IntelliJ IDEA <2026.2 Remote Dev Unauth File Access In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Intellij Idea
CVE-2026-64813 Jul 23, 2026
Unauthorized Settings Mod in IntelliJ IDEA <2026.2 Remote Dev In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Intellij Idea
CVE-2026-64812 Jul 23, 2026
IntelliJ IDEA <2026.2 unauthorized input injection in Remote Dev session In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Intellij Idea
CVE-2026-64811 Jul 23, 2026
JetBrains IntelliJ IDEA <2026.2: Dev Cont Config Assignor ATE In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Intellij Idea
CVE-2026-64810 Jul 23, 2026
JetBrains IntelliJ IDEA 2026.1: HTML Injection in IDE Notifications In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Intellij Idea
CVE-2026-64809 Jul 23, 2026
JetBrains PhpStorm <2026.2 ACR via Interpreter Assigner In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
Phpstorm
CVE-2026-64808 Jul 23, 2026
PhpStorm <2026.2: Arbitrary Code Exec via Tooling Assigner In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Phpstorm
CVE-2026-64807 Jul 23, 2026
WebStorm before 2026.2 arbitrary code exec via linter config assigner In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Webstorm
CVE-2026-64806 Jul 23, 2026
JetBrains WebStorm <2026.2: Node.js Interpreter Assigner ATE In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Webstorm
CVE-2026-64805 Jul 23, 2026
JetBrains WebStorm <=2026.1: ATE via package-manager tooling In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Webstorm
CVE-2026-64804 Jul 23, 2026
JetBrains WebStorm <2026.2 ACE via Project-Local Linter Tooling In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
Webstorm
CVE-2026-64802 Jul 23, 2026
Arbitrary Code Exec in GoLand <2026.2 via Go Modules Trust In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
Goland
CVE-2026-64803 Jul 23, 2026
JBL GoLand <=2026.1 ARC via Go SDK assigner In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
Goland
CVE-2026-64800 Jul 23, 2026
JetBrains GoLand <2026.2: Sensitive Config Logged (CVE-2026-64800) In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Goland
CVE-2026-62422 Jul 14, 2026
Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB Access In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Youtrack
CVE-2026-61492 Jul 10, 2026
JetBrains YouTrack XSS via article title in digest email before 2026.2.17394 In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Youtrack
CVE-2026-59796 Jul 10, 2026
JetBrains TeamCity <2026.1.2: Pipeline Mod via Improper Perm Checks In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
Teamcity
CVE-2026-59795 Jul 10, 2026
TeamCity XSS via unauth agent reg before 2026.1.2 (JetBrains) In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Teamcity
CVE-2026-59794 Jul 10, 2026
JetBrains TeamCity <2026.1.2 XSS via Agent Reported Data on Cloud Profile In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
Teamcity
CVE-2026-59793 Jul 10, 2026
TeamCity < 2026.1.2 Perforce VCS arbitrary file access In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
Teamcity
CVE-2026-59792 Jul 10, 2026
JetBrains IntelliJ IDEA <2026.1.4: Path Traversal Exec via Workspace ID In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Intellij Idea
CVE-2026-59791 Jul 10, 2026
YouTrack <2026.2.17012: CSS Injection via Mermaid Diagram In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
Youtrack
CVE-2026-53914 Jun 26, 2026
JetBrains Kotlin <2.4.20 Uns. Deser. in Build Cache Metadata Assigner In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Kotlin
CVE-2026-57926 Jun 26, 2026
Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox Bridge In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Youtrack
CVE-2026-57925 Jun 26, 2026
YouTrack <2026.2.16593 Improper Access Control Read Queries & Tags In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Youtrack
CVE-2026-57924 Jun 26, 2026
YouTrack <=2026.2.16593 Default Role Config Exposes User Profile Details In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Youtrack
CVE-2026-57923 Jun 26, 2026
YouTrack <2026.2.16593 Improper Auth on App Config Endpoint In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
Youtrack
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.