JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any JetBrains product.
RSS Feeds for JetBrains security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by JetBrains Sorted by Most Security Vulnerabilities since 2018
Known Exploited JetBrains Vulnerabilities
The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| JetBrains TeamCity Deserialization of Untrusted Data Vulnerability |
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. CVE-2026-63077 |
August 5, 2026 |
| JetBrains TeamCity Relative Path Traversal Vulnerability |
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. CVE-2024-27199 Exploit Probability: 100.0% |
April 20, 2026 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CVE-2024-27198 Exploit Probability: 99.9% |
March 7, 2024 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CVE-2023-42793 Exploit Probability: 100.0% |
October 4, 2023 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 69 vulnerabilities in JetBrains with an average score of 6.9 out of ten. Last year, in 2025 JetBrains had 84 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in JetBrains in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.84.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 69 | 6.91 |
| 2025 | 84 | 6.07 |
| 2024 | 103 | 6.20 |
| 2023 | 54 | 6.54 |
| 2022 | 75 | 6.48 |
| 2021 | 88 | 6.66 |
| 2020 | 57 | 6.38 |
| 2019 | 57 | 8.28 |
| 2018 | 2 | 0.00 |
It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JetBrains Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-63077 | Jul 27, 2026 |
JetBrains TeamCity <2026.1.3 Remote Code Execution via Agent PollingIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
|
| CVE-2026-65907 | Jul 23, 2026 |
TeamCity <2026.1.2 Git VCS CodeExec VulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
|
| CVE-2026-65908 | Jul 23, 2026 |
JetBrains PyCharm <2026.1.4, 2026.2 Arbitrary Exec via Malicious PythonIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open |
|
| CVE-2026-65906 | Jul 23, 2026 |
TeamCity RCE via Kotlin DSL sandbox escape before 2026.1.2/2025.11.6In JetBrains TeamCity before 2026.1.2, 2025.11.6 ode execution via Kotlin DSL sandbox escape was possible |
|
| CVE-2026-64815 | Jul 23, 2026 |
IntelliJ IDEA UI Designer Form Files Code Injection <2026.2In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files |
|
| CVE-2026-64814 | Jul 23, 2026 |
IntelliJ IDEA <2026.2 Remote Dev Unauth File AccessIn JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session |
|
| CVE-2026-64813 | Jul 23, 2026 |
Unauthorized Settings Mod in IntelliJ IDEA <2026.2 Remote DevIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session |
|
| CVE-2026-64812 | Jul 23, 2026 |
IntelliJ IDEA <2026.2 unauthorized input injection in Remote Dev sessionIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session |
|
| CVE-2026-64811 | Jul 23, 2026 |
JetBrains IntelliJ IDEA <2026.2: Dev Cont Config Assignor ATEIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration |
|
| CVE-2026-64810 | Jul 23, 2026 |
JetBrains IntelliJ IDEA 2026.1: HTML Injection in IDE NotificationsIn JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking |
|
| CVE-2026-64809 | Jul 23, 2026 |
JetBrains PhpStorm <2026.2 ACR via Interpreter AssignerIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter |
|
| CVE-2026-64808 | Jul 23, 2026 |
PhpStorm <2026.2: Arbitrary Code Exec via Tooling AssignerIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling |
|
| CVE-2026-64807 | Jul 23, 2026 |
WebStorm before 2026.2 arbitrary code exec via linter config assignerIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration |
|
| CVE-2026-64806 | Jul 23, 2026 |
JetBrains WebStorm <2026.2: Node.js Interpreter Assigner ATEIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter |
|
| CVE-2026-64805 | Jul 23, 2026 |
JetBrains WebStorm <=2026.1: ATE via package-manager toolingIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling |
|
| CVE-2026-64804 | Jul 23, 2026 |
JetBrains WebStorm <2026.2 ACE via Project-Local Linter ToolingIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling |
|
| CVE-2026-64803 | Jul 23, 2026 |
JBL GoLand <=2026.1 ARC via Go SDK assignerIn JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK |
|
| CVE-2026-64802 | Jul 23, 2026 |
Arbitrary Code Exec in GoLand <2026.2 via Go Modules TrustIn JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration |
|
| CVE-2026-64800 | Jul 23, 2026 |
JetBrains GoLand <2026.2: Sensitive Config Logged (CVE-2026-64800)In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default |
|
| CVE-2026-62422 | Jul 14, 2026 |
Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB AccessIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible |
|
| CVE-2026-61492 | Jul 10, 2026 |
JetBrains YouTrack XSS via article title in digest email before 2026.2.17394In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible |
|
| CVE-2026-59796 | Jul 10, 2026 |
JetBrains TeamCity <2026.1.2: Pipeline Mod via Improper Perm ChecksIn JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks |
|
| CVE-2026-59795 | Jul 10, 2026 |
TeamCity XSS via unauth agent reg before 2026.1.2 (JetBrains)In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
|
| CVE-2026-59794 | Jul 10, 2026 |
JetBrains TeamCity <2026.1.2 XSS via Agent Reported Data on Cloud ProfileIn JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
|
| CVE-2026-59793 | Jul 10, 2026 |
TeamCity < 2026.1.2 Perforce VCS arbitrary file accessIn JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration |
|
| CVE-2026-59792 | Jul 10, 2026 |
JetBrains IntelliJ IDEA <2026.1.4: Path Traversal Exec via Workspace IDIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible |
|
| CVE-2026-59791 | Jul 10, 2026 |
YouTrack <2026.2.17012: CSS Injection via Mermaid DiagramIn JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible |
|
| CVE-2026-53914 | Jun 26, 2026 |
JetBrains Kotlin <2.4.20 Uns. Deser. in Build Cache Metadata AssignerIn JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata |
|
| CVE-2026-57926 | Jun 26, 2026 |
Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox BridgeIn JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
|
| CVE-2026-57925 | Jun 26, 2026 |
YouTrack <2026.2.16593 Improper Access Control Read Queries & TagsIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags |
|
| CVE-2026-57924 | Jun 26, 2026 |
YouTrack <=2026.2.16593 Default Role Config Exposes User Profile DetailsIn JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details |
|
| CVE-2026-57923 | Jun 26, 2026 |
YouTrack <2026.2.16593 Improper Auth on App Config EndpointIn JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings |
|
| CVE-2026-57922 | Jun 26, 2026 |
JetBrains YouTrack 2026.2.16593 Project Settings Disclosure via MCPIn JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible |
|
| CVE-2026-57921 | Jun 26, 2026 |
YouTrack <2026.2.16593 Improper Access: Read Private Data via Comment TemplatesIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint |
|
| CVE-2026-56142 | Jun 19, 2026 |
Privilege Escalation in JetBrains Hub <2026.1.13757 via Auth Details AttachIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible |
|
| CVE-2026-50242 | Jun 19, 2026 |
JetBrains Hub <2026.1.13757 Auth bypass via DB accessIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible |
|
| CVE-2026-56141 | Jun 19, 2026 |
Account takeover via predictable restore codes in JetBrains Hub before 2026.1.13757In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible |
|
| CVE-2026-53915 | Jun 19, 2026 |
GoLand RCE via Untrusted Assigner in Project Config before 2026.1.3 (JetBrains)In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration |
|
| CVE-2026-49386 | May 29, 2026 |
Improper Access Control in JetBrains YouTrack <2026.1.13570 (Planning Canvas)In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas |
|
| CVE-2026-49385 | May 29, 2026 |
YouTrack <2026.1.13570 Improper ACL: Low-Privileged Modifies Service AccountsIn JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts |
|
| CVE-2026-49384 | May 29, 2026 |
PyCharm <2025.3.4 Stored XSS via Jupyter MarkdownIn JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible |
|
| CVE-2026-49383 | May 29, 2026 |
JETBRAINS INTELLIJ IDEA <2026.1 UI Designer XXE in Form ParserIn JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
|
| CVE-2026-49382 | May 29, 2026 |
IntelliJ IDEA <2026.1: Template Injection Exec CVE-2026-49382In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
|
| CVE-2026-49381 | May 29, 2026 |
TeamCity XSS via Stored SAML login before 2026.1In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
|
| CVE-2026-49379 | May 29, 2026 |
Thread Names Assigner Exposes Credentials in JetBrains TeamCity <2026.1In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
|
| CVE-2026-49378 | May 29, 2026 |
JetBrains TeamCity <=2026.1 Credential Exposure via AutocompleteIn JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
|
| CVE-2026-49380 | May 29, 2026 |
JetBrains TeamCity <2026.1 SAML Plugin Open RedirectIn JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
|
| CVE-2026-49377 | May 29, 2026 |
JetBrains TeamCity <=2025.11.1 Default Agent Params expose sensitive dataIn JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
|
| CVE-2026-49376 | May 29, 2026 |
TeamCity<2026.1 Insufficient Username Validation in SAML Plugin AssignerIn JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
|
| CVE-2026-49375 | May 29, 2026 |
JetBrains TeamCity <2026.1 Reflected XSS on Repo Download PageIn JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page |
|