Jetbrains CVE-2026-63077 Zero-Day Added to CISA KEV Under Active Exploitation
Key findings • Jetbrains CVE-2026-63077 added to CISA KEV due to active exploitation. • The vulnerability is confirmed as a zero-day exploit. • Immediate patching of all affected Jetbrain…

Key findings
- Jetbrains CVE-2026-63077 added to CISA KEV due to active exploitation.
- The vulnerability is confirmed as a zero-day exploit.
- Immediate patching of all affected Jetbrains products is critical.
- CISA mandates remediation by August 5, 2026, for federal agencies.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert by adding a newly identified Jetbrains vulnerability, CVE-2026-63077, to its authoritative Known Exploited Vulnerabilities (KEV) Catalog. This inclusion signifies that the flaw is under active exploitation by malicious actors in real-world attacks, elevating its risk profile significantly. The KEV catalog serves as a crucial resource for federal civilian executive branch agencies, mandating the remediation of listed vulnerabilities within specified deadlines due to their proven threat.
Designated as CVE-2026-63077, this specific vulnerability within the Jetbrains ecosystem has been confirmed as a zero-day exploit, meaning adversaries were leveraging it before a patch was widely available. While specific details regarding the nature of the exploit are still emerging, its presence in the KEV catalog underscores its severity and the immediate danger it poses to unpatched systems. Organizations utilizing Jetbrains products should consider this a high-priority threat.
The active exploitation of CVE-2026-63077 necessitates an urgent response from all organizations, not just federal entities. Attackers are actively scanning for and compromising vulnerable systems, potentially leading to unauthorized access, data breaches, or further system compromise. The window of opportunity for defenders to mitigate this risk is closing rapidly as threat actors continue to weaponize this flaw.
To counter this immediate threat, defenders are strongly advised to identify and patch all instances of affected Jetbrains products without delay. CISA's Binding Operational Directive (BOD 22-01) mandates that federal agencies remediate KEV vulnerabilities by a specific due date, which for CVE-2026-63077 is August 5, 2026. All other organizations should adopt a similar urgency, prioritizing the application of vendor-provided security updates to protect their environments from ongoing attacks. Regular vulnerability scanning and robust patch management practices are essential to prevent exploitation.