JetBrains has issued security fixes for multiple products, with national cyber agencies and downstream scanners warning that IntelliJ IDEA, YouTrack, Ktor, and PyCharm contain vulnerabilities requiring updates. Advisories from the Canadian Centre for Cyber Security and Guyana National CIRT direct administrators to JetBrains' fixed-issues guidance and note that affected builds span several release lines, particularly across IntelliJ IDEA and YouTrack deployments.
Tenable plugin coverage adds technical detail for the patched flaws, including IntelliJ IDEA issues such as CVE-2026-75057 involving git credential disclosure and a broader set of six vulnerabilities tied to CWE-611, CWE-77, CWE-78, and CWE-918. For YouTrack, published fixes address CVE-2026-75044, CVE-2026-75045, CVE-2026-75046, CVE-2026-75048, and CVE-2026-75050, covering missing authorization, authentication weaknesses, stored XSS, and denial-of-service conditions; several are described as network-accessible with meaningful confidentiality, integrity, or availability impact. No exploitation activity or threat actor has been identified in the referenced notices, but organizations running affected versions are being urged to apply the patched releases.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
On August 21, 2026, Guyana National CIRT published a JetBrains security notice summarizing affected versions of IntelliJ IDEA, Ktor, PyCharm, and YouTrack. The notice referenced JetBrains' August 17 advisory and the Canadian Centre for Cyber Security's August 18 advisory, and recommended applying updates.
On August 18, 2026, the Canadian Centre for Cyber Security published advisory AV26-825 about vulnerabilities affecting multiple JetBrains products. The notice urged users and administrators to review JetBrains' fixed security issues page and apply updates as they become available.
On August 17, 2026, JetBrains published and patched CVE-2026-75050 in YouTrack. The vulnerability is mapped to CWE-770 and affects versions prior to patched builds including 2026.1.13901 and 2026.2.17950.
On August 17, 2026, JetBrains published and patched CVE-2026-75048, a stored XSS vulnerability in YouTrack. The flaw is classified as CWE-79 and affects versions prior to 2026.2.18068.
On August 17, 2026, JetBrains published and patched CVE-2026-75046 affecting YouTrack. The issue is mapped to CWE-862 and fixed in YouTrack 2026.2.18112.
On August 17, 2026, JetBrains published and patched CVE-2026-75045 in YouTrack. The flaw is mapped to CWE-288 and affects versions prior to patched releases including 2025.3.156085 and 2026.1.13913.
On August 17, 2026, JetBrains published and patched CVE-2026-75044 affecting YouTrack. The vulnerability is classified as CWE-862 and impacts versions prior to patched YouTrack builds including 2025.3.156085, 2026.1.13914, and 2026.2.17917.
On August 17, 2026, JetBrains published and patched six IntelliJ IDEA vulnerabilities: CVE-2026-75052, CVE-2026-75053, CVE-2026-75054, CVE-2026-75055, CVE-2026-75056, and CVE-2026-75058. The issues affect versions prior to 2026.2.1 and are associated with CWEs including CWE-611, CWE-77, CWE-78, and CWE-918.
On August 17, 2026, JetBrains published and patched CVE-2026-75057, a Git credential disclosure issue in IntelliJ IDEA. The flaw is mapped to CWE-532 and affects versions prior to 2026.1.5.
JetBrains issued a security advisory dated August 17, 2026 covering fixed security issues in IntelliJ IDEA, Ktor, PyCharm, and YouTrack. The advisory identified multiple vulnerable version ranges and corresponding patched releases, including IntelliJ IDEA 2026.1.5 and 2026.2.1, Ktor 3.4.1, PyCharm 2026.2.1, and several YouTrack builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.