JetBrains fixes 12 high-severity flaws in YouTrack, Hub, IntelliJ IDEA and TeamCity: update self-hosted servers
EditorialBy TrustList Editorial
Italy’s national cyber agency reports JetBrains updates fixing many flaws, 12 rated high, in YouTrack (before 2026.2.19422), Hub, IntelliJ IDEA (before 2026.2.3) and TeamCity (before 2026.1.4 or 2025.11.8). No exploitation reported.
- Cybersecurity
- Vulnerability Management
- Patch Management
- DevOps
- +1 more
About JetBrains fixes 12 high-severity flaws in YouTrack, Hub, IntelliJ IDEA and TeamCity: update self-hosted servers
JetBrains fixes 12 high-severity flaws in YouTrack, Hub, IntelliJ IDEA and TeamCity: update self-hosted servers
1 October 2026 — JetBrains has released security updates for several of its products, fixing a number of flaws, 12 of them rated high. Italy's national cybersecurity agency (ACN), through CSIRT Italia, published an alert on 1 October 2026 and recommends updating, in line with JetBrains' own guidance.
Not yet independently verified. The affected versions and severity come from CSIRT Italia’s alert. JetBrains’ own list of fixed security issues loads only in a browser and could not be read here, so the per-flaw details and dates have not been checked against it. We will update this when it can be confirmed, and remove this note.
Affected versions
According to CSIRT Italia:
| Product | Vulnerable versions |
|---|---|
| YouTrack | before 2026.2.19422 |
| Hub | before 2026.2.52366 |
| IntelliJ IDEA | before 2026.2.3 |
| TeamCity 2026.1.x | before 2026.1.4 |
| TeamCity 2025.x | before 2025.11.8 |
The flaw types listed are remote code execution, information disclosure, data manipulation, privilege escalation, bypass of security restrictions and spoofing. The 12 high-severity CVEs are CVE-2026-100277, -100273, -100268, -100266, -100262, -100256, -100255, -100254, -100253, -103493, -103490 and -103488. The agency's table shows no public proof-of-concept and no exploitation for any of them, and it rates the systemic impact as high.
Why TeamCity and YouTrack matter most
IntelliJ IDEA runs on developers' own machines and updates through the IDE. TeamCity and YouTrack are usually self-hosted servers. TeamCity is a CI/CD server that holds source code, build secrets and deployment credentials, and earlier TeamCity flaws have been exploited by attackers within days of disclosure. A server left on an old version is the real exposure here. JetBrains' cloud-hosted editions are updated by JetBrains.
What to do
- Update self-hosted TeamCity to 2026.1.4, or 2025.11.8 if you are on the 2025 line, and YouTrack and Hub to the versions above or later.
- Update IntelliJ IDEA to 2026.2.3 or later across developer machines, through your usual software management.
- Keep CI servers off the open internet or behind single sign-on and a VPN, and review which accounts can change build configurations.
- Check JetBrains' fixed-issues page in a browser for the details of each flaw that affects your setup.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- DevOps
- Software Development
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.