Vendor
JetBrains
As of , 4 JetBrains vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2026-63077.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-63077Deserialization of Untrusted Data | JetBrains TeamCity | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.90 | ||
| 2 | CVE-2024-27199Relative Path Traversal | JetBrains TeamCity | Patch nowRansomware use, listed within a year | 0.99 | ||
| 3 | CVE-2024-27198Authentication Bypass | JetBrains TeamCity | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 4 | CVE-2023-42793Authentication Bypass | JetBrains TeamCity | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2023 | 1 |
| 2024 | 1 |
| 2025 | none |
| 2026 | 2 |