16 Total CVEs
6 AI Analyzed
0 CISA KEV
1 Critical
All Vendors
Showing 1-16 of 16 CVEs
CVE-2026-4924
8.2
Devolutions Multiple Products

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026

2026-04-02
CVE-2026-4828
8.2
Devolutions Multiple Products

Improper authentication in the OAuth login functionality in Devolutions Server 2026

2026-04-02
CVE-2026-19768
Analyzed
8.1
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026

2026-08-16
CVE-2026-17568
Analyzed
8.8
Devolutions Server

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the u...

2026-07-29
CVE-2026-16801
Analyzed
8.8
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026

2026-07-25
CVE-2026-16800
Analyzed
8.8
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026

2026-07-25
CVE-2026-15641
7.1
Devolutions Server

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to...

2026-07-20
CVE-2026-15637
7.5
Devolutions Server

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low...

2026-07-20
CVE-2026-14536
Analyzed
9.8
Devolutions Server

Devolutions Server 2026.2.4.0 through 2026.2.9.0 fails to enforce mandatory multi-factor authentication (MFA) policies when encountering invalid defau...

2026-07-11
CVE-2026-12161
Analyzed
8.8
Devolutions Remote Desktop Manager

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026

2026-06-17
CVE-2025-8312
7.1
Devolutions Multiple Products

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due...

2025-07-30
CVE-2025-6741
7.7
Devolutions Multiple Products

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure me...

2025-07-23
CVE-2025-6523
7.7
Devolutions Multiple Products

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via br...

2025-07-23
CVE-2025-12485
8.8
Devolutions Multiple Products

Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025

2025-11-06
CVE-2025-11957
8.4
Devolutions Multiple Products

Improper authorization in the temporary access workflow of Devolutions Server 2025

2025-10-22
CVE-2025-11619
8.8
Devolutions Multiple Products

Improper certificate validation when connecting to gateways in Devolutions Server 2025

2025-10-15