JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any JetBrains product.
RSS Feeds for JetBrains security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by JetBrains Sorted by Most Security Vulnerabilities since 2018
Known Exploited JetBrains Vulnerabilities
The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| JetBrains TeamCity Deserialization of Untrusted Data Vulnerability |
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. CVE-2026-63077 |
August 5, 2026 |
| JetBrains TeamCity Relative Path Traversal Vulnerability |
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. CVE-2024-27199 Exploit Probability: 100.0% |
April 20, 2026 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CVE-2024-27198 Exploit Probability: 99.9% |
March 7, 2024 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CVE-2023-42793 Exploit Probability: 100.0% |
October 4, 2023 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 87 vulnerabilities in JetBrains with an average score of 6.8 out of ten. Last year, in 2025 JetBrains had 84 security vulnerabilities published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.75.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 87 | 6.83 |
| 2025 | 84 | 6.07 |
| 2024 | 103 | 6.20 |
| 2023 | 54 | 6.54 |
| 2022 | 75 | 6.48 |
| 2021 | 88 | 6.66 |
| 2020 | 57 | 6.38 |
| 2019 | 57 | 8.28 |
| 2018 | 2 | 0.00 |
It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JetBrains Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-75060 | Aug 17, 2026 |
Unauthenticated code exec in JetBrains PyCharm <2026.2.1 via Jupyter MCPIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools |
|
| CVE-2026-75059 | Aug 17, 2026 |
JetBrains PyCharm Code Execution via Quick Documentation (Before 2026.2.1)In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible |
|
| CVE-2026-75058 | Aug 17, 2026 |
IntelliJ IDEA Pre2026.2.1 xXE via Eclipse Settings ImporterIn JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers |
|
| CVE-2026-75057 | Aug 17, 2026 |
IntelliJ IDEA <2026.1.5 - Git Credentials Logged in PlaintextIn JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log |
|
| CVE-2026-75056 | Aug 17, 2026 |
Remote Code Exec in IntelliJ IDEA <2026.2.1 via Markdown ExportIn JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible |
|
| CVE-2026-75055 | Aug 17, 2026 |
IntelliJ IDEA <2026.2.1, Hadoop ResourceManager XXE Local File ReadIn JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE |
|
| CVE-2026-75054 | Aug 17, 2026 |
IntelliJ IDEA <2026.2.1 sSRF via OpenAPI preview proxyIn JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects |
|
| CVE-2026-75053 | Aug 17, 2026 |
SRF in JetBrains IntelliJ IDEA < 2026.2.1 via DevKit Debug ListenerIn JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
|
| CVE-2026-75052 | Aug 17, 2026 |
CVE-2026-75052: CMD exec via Markdown preview in IntelliJ IDEA < 2026.2.1In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects |
|
| CVE-2026-75051 | Aug 17, 2026 |
YouTrack 2026.2.17917: Unauthorized Project Transfer Between OrgsIn JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible |
|
| CVE-2026-75050 | Aug 17, 2026 |
YouTrack DoS via crafted type params in <2026.1.13901 & 2026.2.17950In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters |
|
| CVE-2026-75049 | Aug 17, 2026 |
YouTrack Auth Read Rstrctd Articles via Draft-Create EP (v1.13903/v2.17950)In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint |
|
| CVE-2026-75048 | Aug 17, 2026 |
JetBrains YouTrack <2026.2.18068 XSS via Code LabelIn JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible |
|
| CVE-2026-75047 | Aug 17, 2026 |
JetBrains YouTrack DoS via decompression bomb (pre-2026.2.18177)In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint |
|
| CVE-2026-75046 | Aug 17, 2026 |
YouTrack <=2026.2.18112: Auth User Enum via Search (CVE-2026-75046)In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint |
|
| CVE-2026-75045 | Aug 17, 2026 |
JetBrains YouTrack < 2025.3.156085, 2026.x: Unauth DB backup via draft sigIn JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |
|
| CVE-2026-75044 | Aug 17, 2026 |
JetBrains YouTrack 2026.2.18095: Auth Deletion via Mailbox EndptIn JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint |
|
| CVE-2026-68762 | Aug 17, 2026 |
Ktor WebSocket Decompression DoS before 3.4.1In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible |
|
| CVE-2026-63077 | Jul 27, 2026 |
JetBrains TeamCity <2026.1.3 Remote Code Execution via Agent PollingIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
|
| CVE-2026-65907 | Jul 23, 2026 |
TeamCity <2026.1.2 Git VCS CodeExec VulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
|
| CVE-2026-65908 | Jul 23, 2026 |
JetBrains PyCharm <2026.1.4, 2026.2 Arbitrary Exec via Malicious PythonIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open |
|
| CVE-2026-65906 | Jul 23, 2026 |
TeamCity RCE via Kotlin DSL sandbox escape before 2026.1.2/2025.11.6In JetBrains TeamCity before 2026.1.2, 2025.11.6 ode execution via Kotlin DSL sandbox escape was possible |
|
| CVE-2026-64815 | Jul 23, 2026 |
IntelliJ IDEA UI Designer Form Files Code Injection <2026.2In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files |
|
| CVE-2026-64814 | Jul 23, 2026 |
IntelliJ IDEA <2026.2 Remote Dev Unauth File AccessIn JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session |
|
| CVE-2026-64813 | Jul 23, 2026 |
Unauthorized Settings Mod in IntelliJ IDEA <2026.2 Remote DevIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session |
|
| CVE-2026-64812 | Jul 23, 2026 |
IntelliJ IDEA <2026.2 unauthorized input injection in Remote Dev sessionIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session |
|
| CVE-2026-64811 | Jul 23, 2026 |
JetBrains IntelliJ IDEA <2026.2: Dev Cont Config Assignor ATEIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration |
|
| CVE-2026-64810 | Jul 23, 2026 |
JetBrains IntelliJ IDEA 2026.1: HTML Injection in IDE NotificationsIn JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking |
|
| CVE-2026-64809 | Jul 23, 2026 |
JetBrains PhpStorm <2026.2 ACR via Interpreter AssignerIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter |
|
| CVE-2026-64808 | Jul 23, 2026 |
PhpStorm <2026.2: Arbitrary Code Exec via Tooling AssignerIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling |
|
| CVE-2026-64807 | Jul 23, 2026 |
WebStorm before 2026.2 arbitrary code exec via linter config assignerIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration |
|
| CVE-2026-64806 | Jul 23, 2026 |
JetBrains WebStorm <2026.2: Node.js Interpreter Assigner ATEIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter |
|
| CVE-2026-64805 | Jul 23, 2026 |
JetBrains WebStorm <=2026.1: ATE via package-manager toolingIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling |
|
| CVE-2026-64804 | Jul 23, 2026 |
JetBrains WebStorm <2026.2 ACE via Project-Local Linter ToolingIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling |
|
| CVE-2026-64802 | Jul 23, 2026 |
Arbitrary Code Exec in GoLand <2026.2 via Go Modules TrustIn JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration |
|
| CVE-2026-64803 | Jul 23, 2026 |
JBL GoLand <=2026.1 ARC via Go SDK assignerIn JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK |
|
| CVE-2026-64800 | Jul 23, 2026 |
JetBrains GoLand <2026.2: Sensitive Config Logged (CVE-2026-64800)In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default |
|
| CVE-2026-62422 | Jul 14, 2026 |
Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB AccessIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible |
|
| CVE-2026-61492 | Jul 10, 2026 |
JetBrains YouTrack XSS via article title in digest email before 2026.2.17394In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible |
|
| CVE-2026-59796 | Jul 10, 2026 |
JetBrains TeamCity <2026.1.2: Pipeline Mod via Improper Perm ChecksIn JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks |
|
| CVE-2026-59795 | Jul 10, 2026 |
TeamCity XSS via unauth agent reg before 2026.1.2 (JetBrains)In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
|
| CVE-2026-59794 | Jul 10, 2026 |
JetBrains TeamCity <2026.1.2 XSS via Agent Reported Data on Cloud ProfileIn JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
|
| CVE-2026-59793 | Jul 10, 2026 |
TeamCity < 2026.1.2 Perforce VCS arbitrary file accessIn JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration |
|
| CVE-2026-59792 | Jul 10, 2026 |
JetBrains IntelliJ IDEA <2026.1.4: Path Traversal Exec via Workspace IDIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible |
|
| CVE-2026-59791 | Jul 10, 2026 |
YouTrack <2026.2.17012: CSS Injection via Mermaid DiagramIn JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible |
|
| CVE-2026-53914 | Jun 26, 2026 |
JetBrains Kotlin <2.4.20 Uns. Deser. in Build Cache Metadata AssignerIn JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata |
|
| CVE-2026-57926 | Jun 26, 2026 |
Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox BridgeIn JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
|
| CVE-2026-57925 | Jun 26, 2026 |
YouTrack <2026.2.16593 Improper Access Control Read Queries & TagsIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags |
|
| CVE-2026-57924 | Jun 26, 2026 |
YouTrack <=2026.2.16593 Default Role Config Exposes User Profile DetailsIn JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details |
|
| CVE-2026-57923 | Jun 26, 2026 |
YouTrack <2026.2.16593 Improper Auth on App Config EndpointIn JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings |
|