JetBrains Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for JetBrains products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

3

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

JetBrains KEVs Added by Year

Loading...

3 JetBrains KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2024-27199

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Confirmed In CISA 24 Apr 2025
CVE-2023-42793

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

Confirmed In CISA 04 Oct 2023
CVE-2024-27198

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Confirmed In CISA 07 Mar 2024

Common Vulnerability Classes (CWE)

  • CWE-288 — Authentication Bypass Using an Alternate Path or Channel 2
  • CWE-23 — Relative Path Traversal 1
  • CWE-306 — Missing Authentication for Critical Function 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology