CVE-2026-53914: JetBrains Kotlin

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Affected products

  • JetBrains Kotlin: before 2.4.20 (fixed in 2.4.20)

Published 2026-06-26. Last modified 2026-06-27.