LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Jetbrains

35 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical8
High26
Medium1
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-63077exploited9.8criticalteamcityIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent 40d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-5024210criticalhubIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 au78d ago
CVE-2026-6481310criticalintellij ideaIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development s44d ago
CVE-2026-6481210criticalintellij ideaIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session44d ago
CVE-2026-6242210criticalyoutrackIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148453d ago
CVE-2026-561429.9criticalhubIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 pr78d ago
CVE-2026-63077exploited9.8criticalteamcityIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent 40d ago
CVE-2026-561419.8criticalhubIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 ac78d ago
CVE-2026-597929.6criticalintellij ideaIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handl57d ago
CVE-2026-597938.8highteamcityIn JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration57d ago
CVE-2026-659068.8highteamcityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible44d ago
CVE-2026-493688.7highyoutrackIn JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible99d ago
CVE-2026-648148.6highintellij ideaIn JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session44d ago
CVE-2026-659088.6highpycharmIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible44d ago
CVE-2026-648058.4highwebstormIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via projec44d ago
CVE-2026-648088.4highphpstormIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via projec44d ago
CVE-2026-648098.4highphpstormIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the co44d ago
CVE-2026-648048.4highwebstormIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via projec44d ago
CVE-2026-648068.4highwebstormIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the co44d ago
CVE-2026-444138.2highteamcityIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access117d ago
CVE-2026-597968.1highteamcityIn JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks57d ago
CVE-2026-597958.1highteamcityIn JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible57d ago
CVE-2026-648158.1highintellij ideaIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files44d ago
CVE-2026-493678highintellij ideaIn JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account99d ago
CVE-2026-648027.8highgolandIn JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Mo44d ago
CVE-2026-648037.8highgolandIn JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the conf44d ago
CVE-2026-648077.8highwebstormIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configurat44d ago
CVE-2026-648117.8highintellij ideaIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via d44d ago
CVE-2026-493667.8highintellij ideaIn JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion99d ago
CVE-2026-493747.6highteamcityIn JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters99d ago
CVE-2026-493727.5highteamcityIn JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible99d ago
CVE-2026-597947.3highteamcityIn JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data57d ago
CVE-2026-539157.1highgolandIn JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration78d ago
CVE-2026-493737.1highteamcityIn JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings99d ago
CVE-2026-493717.1highteamcityIn JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible99d ago
CVE-2026-327456.3mediumdataloreIn JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie sett176d ago

Filter the full tracker by Jetbrains

Our coverage of Jetbrains

breachcritical

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

CVE-2026-63077critical

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

JetBrains TeamCity is affected by CVE-2026-63077, a critical vulnerability allowing unauthenticated remote code execution. An attacker can exploit the agent polling protocol to execute OS commands with the privileges of the TeamCity server process. While initially not known to be exploited, CISA has confirmed its use in the wild.

CVE-2026-63077critical

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.