JetBrains released security updates for unspecified vulnerabilities affecting Hub, IntelliJ IDEA, Rider, TeamCity, and YouTrack. Affected deployments include Hub before 2026.2.52366, IntelliJ IDEA before 2026.2.3, Rider before 2026.2.1, along with specified releases of TeamCity and YouTrack; advisory summaries also identify broader update thresholds across the 2026.2, 2026.1.4, and 2025.11.8 release lines.
The Canadian Centre for Cyber Security and Guyana National CIRT urged administrators to review JetBrains’ fixed-security-issues guidance and update affected installations. The available advisories do not identify CVE numbers, vulnerability classes, severity ratings, or evidence of active exploitation, but organizations using JetBrains development or collaboration infrastructure should prioritize validation and deployment of the applicable fixed versions.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-979 concerning the JetBrains vulnerabilities and recommended that users and administrators review the security information and apply necessary updates.
JetBrains published a security advisory covering unspecified vulnerabilities affecting Hub, IntelliJ IDEA, Rider, TeamCity, and YouTrack. It identified fixed-version thresholds and directed users to its Fixed Security Issues information and available updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.