Exploitation timeline
Threadlinqs has recorded 12 JetBrains CVEs published between and . The busiest month was 2026-05 (6 new CVEs). 1 of them (8%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 12 of 12 tracked JetBrains CVEs.
- CVE-2024-27198critical 9.8KEVRansomwareEPSS 93%
- CVE-2024-27199high 7.3EPSS 82.5%
- CVE-2026-63077critical 9.8EPSS 0.6%
- CVE-2026-49366high 7.8EPSS 0.5%
- CVE-2026-25848critical 9.1EPSS 0.4%
- CVE-2026-49373high 7.1EPSS 0.4%
- CVE-2026-53915high 7.1EPSS 0.3%
- CVE-2026-49370low 3.4EPSS 0.2%
- CVE-2026-49374high 7.6EPSS 0.2%
- CVE-2026-49376medium 6.5EPSS 0.2%
- CVE-2026-49369medium 4.3EPSS 0.2%
- CVE-2026-53914medium 6.7EPSS 0.2%
Products affected
Threadlinqs normalises CPE and CNA product records across all 12 CVEs; 6 distinct JetBrains products are affected. The most frequently affected:
- Teamcity 6 CVEs
- YouTrack 2 CVEs
- GoLand 1 CVE
- Hub 1 CVE
- IntelliJ IDEA 1 CVE
- Kotlin 1 CVE
Threat activity
7 tracked threat campaigns reference JetBrains products or exploit JetBrains CVEs:
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling ProtocolCRITICAL
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.aiHIGH
- Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) MalwareHIGH
- Multiple JetBrains Product Vulnerabilities: Account Takeover, Privilege Escalation, and RCE Across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCityHIGH
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)CRITICAL
Threat actors targeting JetBrains
Named threat actors attributed to campaigns that involve JetBrains products or CVEs, with the number of linked campaigns:
How to prioritise JetBrains patching
This order follows the data Threadlinqs holds for JetBrains, not a generic severity checklist:
- 1 of 12 JetBrains CVEs (8%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2024-27198.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2024-27199 (82.5%), CVE-2026-63077 (0.6%), CVE-2026-49366 (0.5%).
- 3 CVEs score Critical and 5 High on CVSS v3 (maximum 9.8, average 7.2); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.