JetBrains vulnerabilities
16 CVEs tracked
JetBrains appears in this week's reports with multiple critical remote code execution (RCE) vulnerabilities posing significant risks to CI/CD environments. The primary focus is on TeamCity, with CVE-2026-63077 (unauthenticated RCE via unsafe deserialization) and CVE-2026-65906 (Kotlin DSL sandbox escape) highlighted as critical threats; additionally, CVE-2026-75045 in YouTrack allows unauthenticated downloading of database backups. Defenders must immediately apply the released security patches for TeamCity, YouTrack, and PyCharm, paying close attention to any internet-facing TeamCity servers.
Azərbaycanca: JetBrains bu həftə CI/CD mühitləri üçün kritik risklər yaradan bir neçə remote code execution (RCE) zəifliyi ilə bağlı hesabatlarda görünür. Əsasən, TeamCity-də aşkarlanmış CVE-2026-63077 (Unauthenticated RCE via unsafe deserialization) və CVE-2026-65906 (Kotlin DSL sandbox escape) kritik təhlükə kimi vurğulanır; YouTrack-də isə CVE-2026-75045 vasitəsilə autentifikasiya olmadan database backup-lərinin ələ keçirilməsi riski mövcuddur. Müdafiəçilər dərhal TeamCity, YouTrack və PyCharm üçün buraxılmış təhlükəsizlik yeniləmələrini tətbiq etməli, xüsusilə internetə açıq TeamCity serverlərini yoxlamalıdır.
This vendor's CVEs16
- CVE-2026-63077KEVEPSS 88%
- CVE-2026-75054EPSS 0.12%
- CVE-2026-75053EPSS 0.18%
- CVE-2026-75052EPSS 0.13%
- CVE-2026-75051EPSS 0.22%
- CVE-2026-75050EPSS 0.80%
- CVE-2026-75049EPSS 0.26%
- CVE-2026-75048EPSS 0.20%
- CVE-2026-75047EPSS 0.86%
- CVE-2026-75046EPSS 0.21%
- CVE-2026-75045EPSS 0.30%
- CVE-2026-75044EPSS 0.23%
- CVE-2026-68762EPSS 0.29%
- CVE-2026-65908EPSS 0.18%
- CVE-2026-65907EPSS 0.42%
- CVE-2026-65906EPSS 0.54%
This hub is built from skopnix's own reporting on JetBrains: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.