Vendor
Jetbrains vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 111 vulnerabilities in Jetbrains: 0 in the last 7 days and 74 in the last 90 days, 15 of them critical and 4 exploited in the wild. The most recent, CVE-2026-86506, was published on 7 September 2026. 7 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 74
- Critical, all time
- 15
- Exploited in the wild
- 4
About Jetbrains
A software development company that produces integrated development environments and developer productivity tools.
Jetbrains technologies
Latest Jetbrains vulnerabilities
- CVE-2026-86506: JetBrains GoLand missing authentication in profiler's pprof servermediumCVSS 5.9EPSS 0.4%
- CVE-2026-86505: JetBrains IntelliJ IDEA project metadata disclosure to marketplacelowCVSS 3.3EPSS 0.1%
- CVE-2026-86504: JetBrains IntelliJ IDEA Dev Container code execution via missing trust confirmationhighCVSS 7.8EPSS 0.2%
- CVE-2026-86503: JetBrains IntelliJ IDEA SSRF in Kubernetes spec-source URL fetchinglowCVSS 3.3EPSS 0.1%
- CVE-2026-86502: JetBrains IntelliJ IDEA missing TLS and authentication in IJent gRPC serverhighCVSS 8.4EPSS 0.2%
- CVE-2026-86501: JetBrains IntelliJ IDEA information disclosure in terminal logginglowCVSS 2.8EPSS 0.4%
- CVE-2026-86500: JetBrains YouTrack privilege escalation in project permissionsmediumCVSS 5.5EPSS 0.3%
- CVE-2026-86499: JetBrains YouTrack information disclosure in predefined search fieldsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-86498: JetBrains YouTrack authorization bypass in link resourceshighCVSS 7.7EPSS 0.3%
- CVE-2026-86497: JetBrains YouTrack mailbox credential exfiltrationmediumCVSS 6.8EPSS 0.5%
- CVE-2026-86496: JetBrains YouTrack missing access control on Helpdesk authorized reportersmediumCVSS 4.3EPSS 0.3%
- CVE-2026-86495: JetBrains YouTrack missing permission checks in knowledge basemediumCVSS 6.5EPSS 0.3%
- CVE-2026-86494: JetBrains YouTrack unauthorized link modification via whiteboard clonehighCVSS 7.7EPSS 0.3%
- CVE-2026-86493: JetBrains YouTrack privilege escalation in whiteboard cardsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86492: JetBrains YouTrack cross-tenant GitHub App token thefthighCVSS 8.5EPSS 0.9%
- CVE-2026-86491: JetBrains YouTrack stored XSS in icon uploadslowCVSS 3.5EPSS 0.2%
- CVE-2026-86490: JetBrains YouTrack improper permission checks in app importmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86489: JetBrains YouTrack IDOR in user profile APImediumCVSS 6.5EPSS 0.3%
- CVE-2026-86488: JetBrains YouTrack insecure direct object reference in watchRules and issueListConfigmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86487: JetBrains YouTrack WebSocket privilege escalation in whiteboardlowCVSS 3.1EPSS 0.2%
- CVE-2026-86486: JetBrains YouTrack VCS webhook authentication bypasslowCVSS 3.7EPSS 0.3%
- CVE-2026-86485: JetBrains YouTrack IP spoofing via HTTP headers in Bitbucket webhook validationlowCVSS 3.3EPSS 0.2%
- CVE-2026-86484: JetBrains YouTrack stored XSS in assignee names via AngularJS template injectionmediumCVSS 4.6EPSS 0.6%
- CVE-2026-86483: JetBrains YouTrack stored XSS in custom field on Agile boardmediumCVSS 5.4EPSS 0.6%
- CVE-2026-86482: JetBrains YouTrack privilege escalation in role assignment validationhighCVSS 8.8EPSS 0.4%
Most severe Jetbrains vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-63077: JetBrains TeamCity remote code execution in agent polling protocolcriticalexploited in the wildCVSS 9.8EPSS 0.7%
- CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-42793: JetBrains TeamCity Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-27199: JetBrains TeamCity relative path traversal in admin interfacecriticalexploited in the wildCVSS 7.3EPSS 90.9%
- CVE-2026-64813: JetBrains IntelliJ IDEA unauthorized settings modification in Remote DevelopmentcriticalCVSS 10
- CVE-2026-64812: JetBrains IntelliJ IDEA unauthorized input injection in Remote Development sessioncriticalCVSS 10
- CVE-2026-62422: JetBrains YouTrack authentication bypass via direct database accesscriticalCVSS 10
- CVE-2026-50242: JetBrains Hub authentication bypass leading to administrative accesscriticalCVSS 10
- CVE-2026-56142: JetBrains Hub privilege escalation via authentication detail attachmentcriticalCVSS 9.9
- CVE-2026-86478: JetBrains YouTrack Helpdesk unauthenticated account takeover via improper email authenticationcriticalCVSS 9.8EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 7 | 1 | |
| 13 Jul 2026 | 1 | 1 | |
| 20 Jul 2026 | 18 | 3 | |
| 27 Jul 2026 | 1 | 1 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 18 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 29 | 2 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/jetbrains.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jetbrains vulnerabilities", https://junglewise.ai/threats/vendors/jetbrains, 26 September 2026.