Skip to content
TrustList
News

JetBrains fixes 12 high-severity flaws in YouTrack, Hub, IntelliJ IDEA and TeamCity: update self-hosted servers

Editorial

By TrustList Editorial

Italy’s national cyber agency reports JetBrains updates fixing many flaws, 12 rated high, in YouTrack (before 2026.2.19422), Hub, IntelliJ IDEA (before 2026.2.3) and TeamCity (before 2026.1.4 or 2025.11.8). No exploitation reported.

About JetBrains fixes 12 high-severity flaws in YouTrack, Hub, IntelliJ IDEA and TeamCity: update self-hosted servers

JetBrains fixes 12 high-severity flaws in YouTrack, Hub, IntelliJ IDEA and TeamCity: update self-hosted servers

1 October 2026 — JetBrains has released security updates for several of its products, fixing a number of flaws, 12 of them rated high. Italy's national cybersecurity agency (ACN), through CSIRT Italia, published an alert on 1 October 2026 and recommends updating, in line with JetBrains' own guidance.

Not yet independently verified. The affected versions and severity come from CSIRT Italia’s alert. JetBrains’ own list of fixed security issues loads only in a browser and could not be read here, so the per-flaw details and dates have not been checked against it. We will update this when it can be confirmed, and remove this note.

Affected versions

According to CSIRT Italia:

Product Vulnerable versions
YouTrack before 2026.2.19422
Hub before 2026.2.52366
IntelliJ IDEA before 2026.2.3
TeamCity 2026.1.x before 2026.1.4
TeamCity 2025.x before 2025.11.8

The flaw types listed are remote code execution, information disclosure, data manipulation, privilege escalation, bypass of security restrictions and spoofing. The 12 high-severity CVEs are CVE-2026-100277, -100273, -100268, -100266, -100262, -100256, -100255, -100254, -100253, -103493, -103490 and -103488. The agency's table shows no public proof-of-concept and no exploitation for any of them, and it rates the systemic impact as high.

Why TeamCity and YouTrack matter most

IntelliJ IDEA runs on developers' own machines and updates through the IDE. TeamCity and YouTrack are usually self-hosted servers. TeamCity is a CI/CD server that holds source code, build secrets and deployment credentials, and earlier TeamCity flaws have been exploited by attackers within days of disclosure. A server left on an old version is the real exposure here. JetBrains' cloud-hosted editions are updated by JetBrains.

What to do

  • Update self-hosted TeamCity to 2026.1.4, or 2025.11.8 if you are on the 2025 line, and YouTrack and Hub to the versions above or later.
  • Update IntelliJ IDEA to 2026.2.3 or later across developer machines, through your usual software management.
  • Keep CI servers off the open internet or behind single sign-on and a VPN, and review which accounts can change build configurations.
  • Check JetBrains' fixed-issues page in a browser for the details of each flaw that affects your setup.

Sources

Categories & features