📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

JetBrains s.r.o.

Jetbrains PyCharm 2026.2

Latest tracked version 2026.2. Release status, tracked CVEs, and automated cross-platform patching for Jetbrains PyCharm.

PlatformLatest versionCVEs trackedLast checked
Windows2026.2102026-08-10

Known vulnerabilities (CVEs) in Jetbrains PyCharm

Lavawall tracks 10 published CVEs affecting Jetbrains PyCharm, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2026-659082026-07-23 13:16:32HIGH (9)In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project openLOCAL
CVE-2026-493842026-05-29 19:16:28MEDIUM (6)In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possibleNETWORK
CVE-2026-258472026-02-09 11:16:15HIGH (8)In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possibleNETWORK
CVE-2024-370512024-06-10 16:15:17HIGH (9)GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4NETWORK
CVE-2022-298212022-04-28 10:15:09MEDIUM (8)In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possibleLOCAL
CVE-2022-298202022-04-28 10:15:08LOW (4)In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possibleADJACENT_NETWORK
CVE-2021-459772022-02-25 15:15:10CRITICAL (10)JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.NETWORK
CVE-2021-300052021-05-11 12:15:08HIGH (8)In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.LOCAL
CVE-2020-116942020-04-10 21:15:12HIGH (8)In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.NETWORK
CVE-2019-149582019-10-02 19:15:15HIGH (8)JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.NETWORK

Why keeping Jetbrains PyCharm patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Jetbrains PyCharm release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Jetbrains PyCharm

Lavawall® watches Jetbrains PyCharm releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Jetbrains PyCharm, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Jetbrains PyCharm?
Lavawall tracks Jetbrains PyCharm at version 2026.2 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Jetbrains PyCharm have known security vulnerabilities (CVEs)?
Lavawall tracks 10 CVEs for Jetbrains PyCharm and remediates them automatically as part of patching.
How do I patch Jetbrains PyCharm automatically?
Deploy the Lavawall® agent and Jetbrains PyCharm updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Jetbrains PyCharm through public information and proprietary statistical analysis, and can patch it automatically across your fleet.