JetBrains released fixes for 18 vulnerabilities affecting multiple developer products, including IntelliJ IDEA, TeamCity, WebStorm, PhpStorm, PyCharm, and GoLand, with the most severe issues concentrated in IntelliJ IDEA Remote Development and TeamCity. Two IntelliJ IDEA flaws, CVE-2026-64812 and CVE-2026-64813, were rated CVSS 10.0 and could allow unauthorized input injection and unauthorized settings modification during Remote Development sessions in versions before 2026.2. JetBrains also fixed CVE-2026-64814, which exposed unauthorized file access in Remote Development, and CVE-2026-64815, an arbitrary code injection issue via UI Designer form files.
Several IDE vulnerabilities could be triggered before project trust was granted, allowing arbitrary code execution through project-local tooling or configured interpreters in WebStorm (CVE-2026-64804, CVE-2026-64805, CVE-2026-64806), PhpStorm (CVE-2026-64808, CVE-2026-64809), and PyCharm (CVE-2026-65908). TeamCity received fixes for CVE-2026-65907, a CVSS 9.1 remote code execution flaw in Git VCS roots, and CVE-2026-65906, a Kotlin DSL sandbox escape affecting versions before 2026.1.2 and 2025.11.6. The Canadian Centre for Cyber Security urged administrators to apply JetBrains’ updates, and available reporting said there was no confirmed in-the-wild exploitation or public proof-of-concept at the time of disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A July 23, 2026 report summarized that JetBrains had fixed 18 vulnerabilities across multiple products, with CVE-2026-64812 and CVE-2026-64813 in IntelliJ IDEA rated CVSS 10.0 and TeamCity flaws CVE-2026-65907 and CVE-2026-65906 also highlighted as severe. The report said JetBrains stated there was no public proof-of-concept or confirmed in-the-wild exploitation.
On July 23, 2026, the Canadian Centre for Cyber Security issued advisory AV26-739 about JetBrains security updates. The notice urged users and administrators to review JetBrains' guidance and apply updates for affected versions of GoLand, IntelliJ IDEA, and PhpStorm.
On July 23, 2026, JetBrains published security advisories and fixes for vulnerabilities affecting several developer products, including GoLand, IntelliJ IDEA, PhpStorm, PyCharm, TeamCity, and WebStorm. Fixed versions referenced in the sources include IntelliJ IDEA 2026.2, PhpStorm 2026.2, WebStorm 2026.2, PyCharm 2026.1.4/2026.2, and TeamCity 2026.1.2/2025.11.6.
Several vulnerability records state that JetBrains received or recorded multiple CVEs on July 23, 2026, affecting WebStorm, PhpStorm, IntelliJ IDEA, and related products. The issues include arbitrary code execution, unauthorized file access, input injection, and settings modification vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecurityonline.info
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.