Devolutions

    Dashboard / Vendors

    Products: 12
    Vulnerabilities: 184
    Known Exploited: 0
    12
    Critical Level Threats
    56
    High Level Threats
    101
    Medium Level Threats
    15
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-78417

    Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.

    Last Modified: Aug 28, 2026
    Published: Aug 24, 2026

    CVE-2026-19768

    Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.

    Last Modified: Aug 14, 2026
    Published: Aug 14, 2026

    CVE-2026-8497

    TLS Certificate Validation Failure Enables Man‑in‑the‑Middle Attacks

    Last Modified: Aug 21, 2026
    Published: Jul 29, 2026

    CVE-2026-17570

    PAM Password History API Allows Credential Disclosure via Improper Access Control

    Last Modified: Aug 12, 2026
    Published: Jul 27, 2026

    CVE-2026-17569

    Improper access control allows view‑only users to retrieve stored API tokens

    Last Modified: Aug 03, 2026
    Published: Jul 27, 2026
    Items Per Page
    Devolutions Vulnerabilities & Security CVEs | CVE-DB