Vendor

JetBrains

As of , 4 JetBrains vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2026-63077.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-63077Deserialization of Untrusted DataJetBrains TeamCityPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.90
2CVE-2024-27199Relative Path TraversalJetBrains TeamCityPatch nowRansomware use, listed within a year0.99
3CVE-2024-27198Authentication BypassJetBrains TeamCityPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2023-42793Authentication BypassJetBrains TeamCityPatch this weekRansomware use; Metasploit module; EPSS 0.990.99

Added each year

0.511.522023: 1120232024: 1120242025: nonenone20252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20231
20241
2025none
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-63077 JetBrains TeamCityRansomware use: Unknown to Known.
  2. CVE-2024-27199 JetBrains TeamCityEdited: notes.
  3. CVE-2024-27199 JetBrains TeamCityRansomware use: Unknown to Known.
  4. CVE-2024-27198 JetBrains TeamCityEdited: notes.

Every change we recorded