In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
CVSSv3.1 8.4 (HIGH)
CWECWE 829VNDJetbrainsTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-23
2026-07-23 12:18Z
HIGH
CVE-2026-64808 — JetBrains: In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
CVSSv3.1 8.4 (HIGH)
CWECWE 829VNDJetbrainsTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-23
2026-07-23 12:18Z
HIGH
CVE-2026-64805 — JetBrains: In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
CVSSv3.1 8.4 (HIGH)
CWECWE 829VNDJetbrainsTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-23
2026-07-23 12:18Z
HIGH
CVE-2026-64804 — JetBrains: In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
CVSSv3.1 8.4 (HIGH)
Check Point released emergency patches for CVE-2026-16232, a critical authentication bypass in SmartConsole (CVSS 9.1) that allows unauthenticated remote attackers to obtain admin tokens and full management server access. The vulnerability is actively exploited in the wild and was added to CISA's KEV list with a 3-day remediation deadline. Two additional critical/high-severity vulnerabilities (CVE-2026-62144, CVE-2026-62145) were patched simultaneously.