These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-63077 is a critical vulnerability in JetBrains TeamCity, allowing unauthenticated remote code execution via the agent polling protocol. The issue exists in versions before 2026.1.3 and 2025.11.7. This vulnerability has a CVSS score of 9.8 and is classified as CRITICAL, indicating a high impact on confidentiality, integrity, and availability. Users of JetBrains TeamCity should prioritize patching [truncated]
CVE-2026-64815 is a high-severity vulnerability in JetBrains IntelliJ IDEA before 2026.2, allowing for arbitrary code injection via UI Designer form files. The vulnerability has a CVSS score of 8.1 and is classified as CWE-94. Limited details are available on affected scope and vendor remediation efforts. Users should verify their deployments and review official advisories for mitigation steps. The CVE re [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:36.897Z and has not been modified since then. CVE-2026-64813 is a critical vulnerability in JetBrains IntelliJ IDEA before version 2026.2, allowing unauthorized settings modification in Remote Development sessions. The vulnerability has a CVSS score of 10 and is tracked under CWE-602. The a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:36.663Z and has not been modified since then. CVE-2026-64811 is a high severity vulnerability in JetBrains IntelliJ IDEA before version 2026.2. The vulnerability allows for arbitrary code execution via development container configuration before granting project trust. The CVSS score for thi [truncated]
JetBrains IntelliJ IDEA before 2026.2 had an HTML injection vulnerability in an IDE notification. This could potentially allow silent user activity tracking. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users of affected versions should review and apply vendor advisories for mitigation. Security teams monitoring for potential user activity tracking and administrators of [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:36.437Z and has not been modified since then. In JetBrains PhpStorm before 2026.2, arbitrary code execution was possible before granting project trust via the configured interpreter. This vulnerability has a CVSS score of 8.4, indicating high severity. The affected product is PhpStorm, and [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:36.323Z and has not been modified since then. In JetBrains PhpStorm before 2026.2, a vulnerability allows for arbitrary code execution before granting project trust via project tooling. This issue has been addressed in version 2026.2.1. The vulnerability has a CVSS score of 8.4, indicating [truncated]
CVE-2026-64807 is a HIGH-severity vulnerability in JetBrains WebStorm before version 2026.2, allowing arbitrary code execution via a project-supplied linter configuration. The vulnerability has a CVSS score of 7.8 and is classified under CWE-829. Users of affected versions should review and update their installations to prevent potential code execution. This vulnerability was published on 2026-07-23T12:18 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:36.103Z and has not been modified since then. In JetBrains WebStorm before 2026.2, a high-severity vulnerability (CVSS score of 8.4) allows for arbitrary code execution before granting project trust via the configured Node.js interpreter. This vulnerability could potentially allow attackers [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:35.993Z and has not been modified since then. CVE-2026-64805 is a high severity vulnerability in JetBrains WebStorm, allowing for arbitrary code execution before granting project trust via project-local package-manager tooling. The vulnerability has a CVSS score of 8.4 and affects WebStorm [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:35.880Z and has not been modified since then. This high-severity vulnerability in JetBrains WebStorm before 2026.2 allows for arbitrary code execution before granting project trust via project-local linter tooling, with a CVSS score of 8.4. The vulnerability impacts users of WebStorm versio [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:35.647Z and has not been modified since then. CVE-2026-64802 is a HIGH-severity vulnerability in JetBrains GoLand before 2026.2, allowing arbitrary code execution before granting project trust in the Go Modules integration. Users of affected product deployments should confirm whether they e [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T12:18:35.527Z and has not been modified since then. This CVE record indicates that JetBrains GoLand before version 2026.2 writes sensitive configuration values to log files by default. Users of JetBrains GoLand before version 2026.2 should review log file management practices and ensure sensitive [truncated]
CVE-2026-62422 is a critical authentication bypass vulnerability in JetBrains YouTrack, allowing direct database access and potentially leading to administrative access. It affects multiple versions of YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. Users should review and patch their systems immediately.
CVE-2026-61492 is a stored XSS vulnerability in JetBrains YouTrack before version 2026.2.17394. The issue allowed for stored XSS via article titles in digest emails. The CVSS score for this vulnerability is 3.5, indicating a low severity. This vulnerability exists due to improper handling of user-supplied input in article titles within digest emails. An attacker with low privileges could potentially injec [truncated]
CVE-2026-59795 is a stored XSS vulnerability in JetBrains TeamCity before version 2026.1.2. The issue allowed for unauthenticated agent registration, potentially leading to malicious script execution. This vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N, indicating a high impact on confidentiality and integrity. User [truncated]
CVE-2026-59794 is a stored XSS vulnerability in JetBrains TeamCity before version 2026.1.2. The vulnerability allows for stored XSS attacks via agent-reported data on the cloud profile page. This type of vulnerability can lead to malicious scripts being executed, potentially resulting in unauthorized actions or data breaches. Users of JetBrains TeamCity, especially those with administrative privileges, sh [truncated]
CVE-2026-59793 is a high-severity vulnerability in JetBrains TeamCity before version 2026.1.2. The issue allows for arbitrary file access due to a flaw in the Perforce VCS integration. This vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Affected users of JetBrains TeamCity, especially those using Perforce VCS integration, should be aware of this vulnerability and take necessary act [truncated]
A critical vulnerability was discovered in JetBrains IntelliJ IDEA before versions 2026.1.4 and 2026.2. This vulnerability, tracked as CVE-2026-59792, allows for code execution via path traversal in project workspace ID handling, posing a significant risk to users of affected versions. The CVSS score for this vulnerability is 9.6, indicating critical severity. Users of JetBrains IntelliJ IDEA prior to 202 [truncated]
A low-severity vulnerability was found in JetBrains YouTrack before version 2026.2.17012. The issue allows for CSS injection via Mermaid diagram rendering. This type of vulnerability can lead to potential styling or rendering issues within the application. Users of JetBrains YouTrack should apply the patch to prevent potential CSS injection attacks. The CVE record was published on 2026-07-10T15:16:48.110Z [truncated]
CVE-2026-56142 is a critical privilege escalation vulnerability in JetBrains Hub. The issue allows attackers to escalate privileges by attaching authentication details to accounts. This vulnerability affects multiple versions of JetBrains Hub, including those prior to 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. The vulnerability has a CVSS score of 9.9, ind [truncated]
CVE-2026-56141 is a critical vulnerability in JetBrains Hub, a software development collaboration tool. The issue allows for account takeover via predictable restore codes. Affected versions include those before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. The vulnerability has a CVSS score of 9.8, indicating a high severity. Defenders should prioritize patc [truncated]
CVE-2026-50242 is a critical authentication bypass vulnerability in JetBrains Hub. The issue allows for direct database access, leading to administrative access. Affected versions include those before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. The CVSS score is 10, indicating the highest severity. Defenders should prioritize patching due to the potential f [truncated]
JetBrains YouTrack versions prior to 2026.1.13570 contain an improper access control vulnerability (CWE-639) in the Planning Canvas feature. An authenticated attacker with low privileges can enumerate restricted issues and articles that should not be accessible to them. The vulnerability has a CVSS 3.1 score of 6.5 (MEDIUM severity) with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating network-based [truncated]
A medium-severity improper access control vulnerability in JetBrains YouTrack before version 2026.1.13570 allows low-privileged users to modify service accounts. The vulnerability stems from missing authorization checks (CWE-862) that fail to restrict service account modification to administrative roles. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) indicates network-accessible attack vector w [truncated]
A stored cross-site scripting (XSS) vulnerability in JetBrains PyCharm before version 2025.3.4 allows malicious JavaScript to persist in Jupyter notebook Markdown cells. The flaw carries a CVSS 3.1 score of 6.1 (Medium) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network attack vector, low attack complexity, no privileges required, user interaction needed, and scope change wit [truncated]
A low-severity XML External Entity (XXE) vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2026.1. The flaw resides in the UI Designer form parser, which processes XML-based form definitions. Successful exploitation could allow information disclosure through local file access when a user opens a maliciously crafted form file. The attack requires local access and user interaction, with no p [truncated]
A template injection vulnerability in the Copyright plugin of JetBrains IntelliJ IDEA before version 2026.1 could allow code execution. The vulnerability, classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine), requires local access with high attack complexity and user interaction. The CVSS 3.1 score of 4.5 reflects limited impacts to confidentiality, integrity, and [truncated]
A stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity before version 2026.1 allows an attacker with administrative privileges to inject malicious scripts into the SAML login page. The vulnerability requires high privileges and user interaction, limiting its exploitability. The CVSS 3.1 score of 3.4 reflects the need for an authenticated administrator to perform the attack and a victim to [truncated]
A low-severity open redirect vulnerability exists in JetBrains TeamCity's SAML authentication plugin prior to version 2026.1. The flaw, classified as CWE-601 (URL Redirection to Untrusted Site), could allow an attacker to redirect users to malicious websites after authentication. The vulnerability requires network access and user interaction, with high attack complexity due to the need to bypass security [truncated]
A credentials exposure vulnerability in JetBrains TeamCity before version 2026.1 allows sensitive information to appear in thread names, potentially exposing credentials to users with local access to process listings or diagnostic outputs. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) indicates network attack vector with low attack complexity, requiring low privileges and yielding high confide [truncated]
A medium-severity information disclosure vulnerability in JetBrains TeamCity before version 2026.1 exposes credential parameters through the parameter autocompletion feature. Authenticated users with low privileges can leverage this UI behavior to discover sensitive credential values that should remain concealed. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) indicates network-accessible attack [truncated]
JetBrains TeamCity versions prior to 2025.11.2 expose sensitive data through default agent parameters. This information disclosure vulnerability (CWE-526) allows authenticated users with low privileges to access sensitive information that should not be exposed by default configuration. The CVSS 3.1 score of 4.3 (Medium severity) reflects network-based attack vector with low attack complexity, requiring lo [truncated]
A medium-severity authentication bypass vulnerability exists in JetBrains TeamCity's SAML plugin prior to version 2026.1. Insufficient username validation during SAML authentication processing could allow an attacker to potentially impersonate legitimate users or gain unauthorized access to the CI/CD platform. The vulnerability stems from improper authorization controls (CWE-863) in the SAML identity prov [truncated]
A reflected cross-site scripting (XSS) vulnerability exists in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5. The flaw affects the repository download page and could allow an attacker to execute malicious scripts in a victim's browser context. The CVSS 3.1 score of 6.1 (MEDIUM) reflects network attack vector, low attack complexity, no privileges required, but user interaction required, with sc [truncated]
A high-severity vulnerability in JetBrains TeamCity before version 2026.1 allows authenticated users with low privileges to access build configuration parameters due to improper permission checks. The vulnerability, published on May 29, 2026, carries a CVSS 3.1 score of 7.6 (HIGH) with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L. The underlying weakness is categorized as CWE-862 (Missing Auth [truncated]
JetBrains TeamCity before version 2026.1 contains a remote code execution vulnerability exploitable through Perforce connection settings. The vulnerability, classified as CWE-88 (Improper Neutralization of Argument Delimiters in a Command), allows an attacker with low privileges to execute arbitrary code on the affected system. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N) indicates network at [truncated]
JetBrains TeamCity versions prior to 2026.1 and 2025.11.5 contain an unauthenticated Server-Side Request Forgery (SSRF) vulnerability exploitable through build status functionality. The flaw allows remote attackers to induce the server to make requests to arbitrary destinations without authentication. With a CVSS 3.1 score of 7.5 (HIGH), this vulnerability presents significant risk as it requires no privi [truncated]
A reflected cross-site scripting (XSS) vulnerability exists in JetBrains TeamCity versions prior to 2026.1.1. The flaw resides in the keyword filter functionality, where insufficient input sanitization allows attacker-controlled script content to execute in a victim's browser context. With a CVSS 3.1 score of 7.1 (High), this vulnerability presents significant risk due to its network attack vector, low at [truncated]
A low-severity information disclosure vulnerability in JetBrains YouTrack before version 2026.1.13162 allows authenticated administrators to inadvertently expose sensitive information through fetchApp requests. The vulnerability, published on May 29, 2026, carries a CVSS 3.1 score of 3.4 (Low severity) with the vector AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N. The attack requires high privileges (administrator [truncated]
A medium-severity information disclosure vulnerability exists in JetBrains YouTrack versions prior to 2026.1.13162. The flaw allows authenticated users to access sensitive information through the Users and Groups pages. The vulnerability was disclosed on 2026-05-29 and is currently undergoing analysis by NVD. No known exploitation in the wild or ransomware campaign use has been reported.
JetBrains YouTrack versions prior to 2026.1.13162 contain a stored cross-site scripting (XSS) vulnerability in project notification templates. An authenticated attacker with low privileges can inject malicious scripts into notification templates, which execute when rendered in other users' browsers. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N) indicates network attack vector, low attack compl [truncated]
A command execution vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2026.1.1. The flaw allows command execution via the guest user account, presenting a significant security risk in multi-user or shared environments where guest access may be enabled. The vulnerability is classified as HIGH severity with a CVSS score of 8.0. The attack vector is network-based with low attack complexity, r [truncated]
A command injection vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2026.1.1. The flaw occurs during filename completion, where unsanitized input can be injected into system commands. This is classified as CWE-78 (OS Command Injection). The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector, low attack complexity, no privileges required, but user interaction needed, with high impa [truncated]
CVE-2024-27199 is a JetBrains TeamCity relative path traversal vulnerability that CISA has added to the Known Exploited Vulnerabilities catalog. Because CISA also records known ransomware campaign use, organizations running TeamCity should treat remediation as urgent and follow vendor and CISA guidance without delay.
CVE-2024-27198 is a JetBrains TeamCity authentication bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-03-07. The source corpus also marks known ransomware campaign use, so defenders should treat this as an urgent exposure rather than a routine patch item. CISA’s required action is to apply vendor mitigations or discontinue use of the product if mitigations are u [truncated]
CVE-2023-42793 affects JetBrains TeamCity and is described as an authentication bypass vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-04, indicating active exploitation concerns and known ransomware campaign use. For defenders, this is a high-priority CI/CD exposure because TeamCity often sits close to build systems, credentials, and release workflows.