jetbrains
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting jetbrains.
- CVE-2026-63077In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocolKEV9.8
- CVE-2026-65907In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible9.1
- CVE-2026-65908In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open8.6
- CVE-2026-65906In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible8.8
- CVE-2026-64815In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files8.1
- CVE-2026-64814In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session8.6
- CVE-2026-64812In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session10.0
- CVE-2026-64811In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration7.8
- CVE-2026-64813In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session10.0
- CVE-2026-64809In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter8.4
- CVE-2026-64808In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling8.4
- CVE-2026-64810In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking4.3
- CVE-2026-64806In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter8.4
- CVE-2026-64807In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration7.8
- CVE-2026-64805In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling8.4