Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-78417
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
CVE-2026-19768
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
CVE-2026-8497
TLS Certificate Validation Failure Enables Man‑in‑the‑Middle Attacks
CVE-2026-17570
PAM Password History API Allows Credential Disclosure via Improper Access Control
CVE-2026-17569
Improper access control allows view‑only users to retrieve stored API tokens
