Skip to content

Products › Server applications and development

Server applications and development

Development and CI/CD

Code forges, continuous integration pipelines, package repositories and developer tools.

For example: Jenkins, GitLab, TeamCity, JFrog Artifactory.

Category RSS feed

Pace of additions

Number of “Development and CI/CD” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20251
Oct 9, 2025 to Nov 7, 20250
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20265
Feb 6, 2026 to Mar 7, 20261
Mar 8, 2026 to Apr 6, 20261
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20261
Jun 6, 2026 to Jul 5, 20260
Jul 6, 2026 to Aug 4, 20260
Aug 5, 2026 to Sep 3, 20264
Sep 4, 2026 to Oct 3, 2026 (in progress)3

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Aqua Security 1 vulnerability · 1 in the last 12 months
  • Atlassian 1 vulnerability
  • Docker 1 vulnerability
  • Git 1 vulnerability
  • Gitea 1 vulnerability · 1 in the last 12 months
  • GitLab 5 vulnerabilities · 3 in the last 12 months
  • Gogs 1 vulnerability · 1 in the last 12 months
  • Jenkins 6 vulnerabilities
  • JetBrains 4 vulnerabilities · 2 in the last 12 months
  • JFrog 4 vulnerabilities · 4 in the last 12 months
  • Nx 1 vulnerability · 1 in the last 12 months
  • PHPUnit 1 vulnerability
  • Prettier 1 vulnerability · 1 in the last 12 months
  • React Native Community 1 vulnerability · 1 in the last 12 months
  • reviewdog 1 vulnerability
  • Sonatype 2 vulnerabilities
  • tj-actions 1 vulnerability
  • Vite 1 vulnerability · 1 in the last 12 months

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    GitLab Community / Enterprise Edition (CE/EE)CVE-2026-85706

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 10.0critical

    Added Sep 11, 2026

  2. Rank 2

    JFrog ArtifactoryCVE-2026-42016

    JFrog Artifactory Incorrect Authorization Vulnerability

    Recently added

    CVSS severity 8.8high

    Added Sep 11, 2026

  3. Rank 3

    JFrog ArtifactoryCVE-2026-42018

    JFrog Artifactory Improper Authentication Vulnerability

    Recently added

    CVSS severity 7.5high

    Added Sep 11, 2026

  4. Rank 4

    JFrog ArtifactoryCVE-2026-82329

    JFrog Artifactory Improper Authentication Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Sep 2, 2026

  5. Rank 5

    GiteaCVE-2026-60004

    Gitea Code Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Aug 25, 2026

  6. Rank 6

    JetBrains TeamCityCVE-2026-63077

    JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

    Hunt for compromise (CISA)Ransomware

    CVSS severity 9.8critical

    Added Aug 5, 2026

  7. Rank 7

    Nx ConsoleCVE-2026-48027

    Nx Console Embedded Malicious Code Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added May 27, 2026

  8. Rank 8

    GitLab Community / Enterprise Edition (CE/EE)CVE-2021-22175

    GitLab Server-Side Request Forgery (SSRF) Vulnerability

    CVE from 2021, added in 2026

    CVSS severity 9.8critical

    Added Feb 18, 2026

  9. Rank 9

    React Native Community React Native CLICVE-2025-11953

    React Native Community CLI OS Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Feb 5, 2026

  10. Rank 10

    Aqua Security TrivyCVE-2026-33634

    Aquasecurity Trivy Embedded Malicious Code Vulnerability

    CVSS severity 8.8high

    Added Mar 26, 2026

Show 24 more vulnerabilities
  1. Rank 11

    GogsCVE-2025-8110

    Gogs Path Traversal Vulnerability

    CVSS severity 8.8high

    Added Jan 12, 2026

  2. Rank 12

    GitLab Community / Enterprise Edition (CE/EE)CVE-2021-39935

    GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    CVE from 2021, added in 2026

    CVSS severity 7.5high

    Added Feb 3, 2026

  3. Rank 13

    ViteCVE-2025-31125

    Vite Vitejs Improper Access Control Vulnerability

    CVSS severity 7.5high

    Added Jan 22, 2026

  4. Rank 14

    Prettier eslint-config-prettierCVE-2025-54313

    Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

    CVSS severity 7.5high

    Added Jan 22, 2026

  5. Rank 15

    JetBrains TeamCityCVE-2024-27199

    JetBrains TeamCity Relative Path Traversal Vulnerability

    RansomwareCVE from 2024, added in 2026

    CVSS severity 7.3high

    Added Apr 20, 2026

  6. Rank 16

    JFrog ArtifactoryCVE-2026-66384

    JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

    CVSS severity 5.3medium

    Added Aug 27, 2026

  7. Rank 17

    GitLab Community / Enterprise Edition (CE/EE)CVE-2021-22205

    GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 10.0critical

    Added Nov 3, 2021

  8. Rank 18

    Jenkins PluginsCVE-2019-1003029

    Jenkins Script Security Plugin Sandbox Bypass Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 9.9critical

    Added Apr 25, 2022

  9. Rank 19

    Jenkins PluginsCVE-2019-1003030

    Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 9.9critical

    Added Mar 25, 2022

  10. Rank 20

    Jenkins CoreCVE-2017-1000353

    Jenkins Remote Code Execution Vulnerability

    CVE from 2017, added in 2025

    CVSS severity 9.8critical

    Added Oct 2, 2025

  11. Rank 21

    Jenkins CoreCVE-2024-23897

    Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Aug 19, 2024

  12. Rank 22

    GitLab Community / Enterprise Edition (CE/EE)CVE-2023-7028

    GitLab Community and Enterprise Editions Improper Access Control Vulnerability

    CVSS severity 9.8critical

    Added May 1, 2024

  13. Rank 23

    JetBrains TeamCityCVE-2024-27198

    JetBrains TeamCity Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Mar 7, 2024

  14. Rank 24

    JetBrains TeamCityCVE-2023-42793

    JetBrains TeamCity Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Oct 4, 2023

  15. Rank 25

    PHPUnitCVE-2017-9841

    PHPUnit Command Injection Vulnerability

    CVE from 2017, added in 2022

    CVSS severity 9.8critical

    Added Feb 15, 2022

  16. Rank 26

    Jenkins CoreCVE-2018-1000861

    Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

    CVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added Feb 10, 2022

  17. Rank 27

    Sonatype Nexus RepositoryCVE-2019-7238

    Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Dec 10, 2021

  18. Rank 28

    Atlassian Bitbucket Server / Data CenterCVE-2022-36804

    Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

    CVSS severity 8.8high

    Added Sep 30, 2022

  19. Rank 29

    Sonatype Nexus RepositoryCVE-2020-10199

    Sonatype Nexus Repository Remote Code Execution Vulnerability

    CVSS severity 8.8high

    Added Nov 3, 2021

  20. Rank 30

    reviewdog action-setup GitHub ActionCVE-2025-30154

    reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

    CVSS severity 8.6high

    Added Mar 24, 2025

  21. Rank 31

    tj-actions changed-files GitHub ActionCVE-2025-30066

    tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

    CVSS severity 8.6high

    Added Mar 18, 2025

  22. Rank 32

    GitCVE-2025-48384

    Git Link Following Vulnerability

    CVSS severity 8.0high

    Added Aug 25, 2025

  23. Rank 33

    Docker DesktopCVE-2019-15752

    Docker Desktop Community Edition Privilege Escalation Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 7.8high

    Added Nov 3, 2021

  24. Rank 34

    Jenkins CoreCVE-2015-5317

    Jenkins User Interface (UI) Information Disclosure Vulnerability

    CVE from 2015, added in 2023

    CVSS severity 7.5high

    Added May 12, 2023

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.