Solution sectors / devtools-ci
Developer Tools & CI/CD
Developer tooling — IDEs, CI/CD pipelines, source control and artifact registries — has deep access to source code and build infrastructure, making it a high-value supply-chain target. This hub tracks CVEs across it.
Cumulative CVEs
7,823
across 249 monthly snapshots
Latest month
230 · proj
-4.2% MoM · +123.3% YoY
Peak month
240
Jun 26
KEV this month
0
41 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem59%
- Mixed21%
- SaaS20%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Developer Tools & CI/CD.
- CVE-2026-16910Quay: ssrf in red hat quay notification webhooks (slack/generic)5.5
- CVE-2026-65907In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible9.1
- CVE-2026-65908In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open8.6
- CVE-2026-65906In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible8.8
- CVE-2026-64815In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files8.1
- CVE-2026-64814In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session8.6
- CVE-2026-64813In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session10.0
- CVE-2026-64812In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session10.0
- CVE-2026-64811In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration7.8
- CVE-2026-64808In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling8.4
- CVE-2026-64809In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter8.4
- CVE-2026-64810In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking4.3
- CVE-2026-64807In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration7.8
- CVE-2026-64806In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter8.4
- CVE-2026-64804In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling8.4
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| build-test-tools | 58 | 13 | · | 15 | — | apache camel (22) · radare2 (9) · hoppscotch (3) |
| artifact-registry | 50 | 11 | · | 5 | — | gitea open source git server (40) · composer (4) · grist-core (3) |
| ide-editor | 45 | 4 | · | 6 | — | coder (20) · microsoft visual studio 2022 version 17.12 (15) · microsoft visual studio 2022 version 17.14 (15) |
| ci-cd | 25 | 2 | · | 7 | — | gitlab (8) · rancher (5) · teamcity (4) |
| — | 18 | · | · | 5 | — | radare2 (9) · enterprise server (4) · vert.x (2) |
| source-control | 4 | · | · | 3 | — | delphix continuous data (1) · forgejo (1) · puppet core (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification