CVE-2026-53914: Critical severity JetBrains Kotlin vulnerability
Published Jun 26, 2026
·Updated
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Affected Software
2 affected components
JetBrains Kotlin<2.4.20
JetBrains Kotlin<2.4.20
Event History
Jun 26, 2026
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53914?
CVE-2026-53914 has a medium severity rating of 6.7.
2
What type of vulnerability is CVE-2026-53914?
CVE-2026-53914 is a code execution vulnerability resulting from unsafe deserialization in the build cache metadata.
3
How do I fix CVE-2026-53914?
To fix CVE-2026-53914, update to JetBrains Kotlin version 2.4.20 or later.
4
What software is affected by CVE-2026-53914?
The vulnerability affects JetBrains Kotlin prior to version 2.4.20.
5
What can attackers achieve through CVE-2026-53914?
Attackers can execute arbitrary code via unsafe deserialization in the affected version of JetBrains Kotlin.