<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Devolutions CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/devolutions/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/devolutions.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical Devolutions vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 16 Aug 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-19768 · CVSS 8.1 · PowerShell Universal</title>
      <link>https://cvebrief.com/cve/cve-2026-19768/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-19768</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Sun, 16 Aug 2026 12:00:00 GMT</pubDate>
      <description>Improper control of generation of code (&apos;Code Injection&apos;) in the settings feature in Devolutions PowerShell Universal 2026 Fix documented: 2026.2.4 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-17568 · CVSS 8.8 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-17568/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-17568</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
      <description>Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request Fix documented: 2026.1.24 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-16800 · CVSS 8.8 · PowerShell Universal</title>
      <link>https://cvebrief.com/cve/cve-2026-16800/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-16800</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Sat, 25 Jul 2026 12:00:00 GMT</pubDate>
      <description>Improper control of generation of code (&apos;Code Injection&apos;) in the schedule feature in Devolutions PowerShell Universal 2026 Fix documented: 2026.2.3 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-16801 · CVSS 8.8 · PowerShell Universal</title>
      <link>https://cvebrief.com/cve/cve-2026-16801/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-16801</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Sat, 25 Jul 2026 12:00:00 GMT</pubDate>
      <description>Improper control of generation of code (&apos;Code Injection&apos;) in the variables feature in Devolutions PowerShell Universal 2026 Fix documented: 2026.2.3 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-15637 · CVSS 7.5 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-15637/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-15637</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Mon, 20 Jul 2026 12:00:00 GMT</pubDate>
      <description>Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the creden Fix documented: 2026.1.23 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-15641 · CVSS 7.1 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-15641/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-15641</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Mon, 20 Jul 2026 12:00:00 GMT</pubDate>
      <description>Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review Fix documented: 2026.1.23 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-14536 · CVSS 9.8 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-14536/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-14536</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Sat, 11 Jul 2026 12:00:00 GMT</pubDate>
      <description>Devolutions Server 2026.2.4.0 through 2026.2.9.0 fails to enforce mandatory multi-factor authentication (MFA) policies when encountering invalid default values, allowing credentialed bypass. Fix documented: 2026.2.9 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-12161 · CVSS 8.8 · Remote Desktop Manager</title>
      <link>https://cvebrief.com/cve/cve-2026-12161/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-12161</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 17 Jun 2026 12:00:00 GMT</pubDate>
      <description>Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-4828 · CVSS 8.2 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-4828/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-4828</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Thu, 02 Apr 2026 12:00:00 GMT</pubDate>
      <description>Improper authentication in the OAuth login functionality in Devolutions Server 2026 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-4924 · CVSS 8.2 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-4924/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-4924</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Thu, 02 Apr 2026 12:00:00 GMT</pubDate>
      <description>Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-4396 · CVSS 8.3 · Hub Reporting Service</title>
      <link>https://cvebrief.com/cve/cve-2026-4396/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-4396</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <description>Improper certificate validation in Devolutions Hub Reporting Service 2025 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-4064 · CVSS 8.3 · PowerShell Universal</title>
      <link>https://cvebrief.com/cve/cve-2026-4064/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-4064</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 18 Mar 2026 12:00:00 GMT</pubDate>
      <description>Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026 Fix documented: 2026.1.4 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-1007 · CVSS 7.6 · Server</title>
      <link>https://cvebrief.com/cve/cve-2026-1007/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2026-1007</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 21 Jan 2026 12:00:00 GMT</pubDate>
      <description>Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-12485 · CVSS 8.8 · Server</title>
      <link>https://cvebrief.com/cve/cve-2025-12485/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2025-12485</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Thu, 06 Nov 2025 12:00:00 GMT</pubDate>
      <description>Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-11957 · CVSS 8.4 · Server</title>
      <link>https://cvebrief.com/cve/cve-2025-11957/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2025-11957</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 22 Oct 2025 12:00:00 GMT</pubDate>
      <description>Improper authorization in the temporary access workflow of Devolutions Server 2025 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-11619 · CVSS 8.8 · Devolutions Server</title>
      <link>https://cvebrief.com/cve/cve-2025-11619/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2025-11619</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 15 Oct 2025 12:00:00 GMT</pubDate>
      <description>Improper certificate validation when connecting to gateways in Devolutions Server 2025 Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-8312 · CVSS 7.1 · Server</title>
      <link>https://cvebrief.com/cve/cve-2025-8312/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2025-8312</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 30 Jul 2025 12:00:00 GMT</pubDate>
      <description>Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-6523 · CVSS 7.7 · Server</title>
      <link>https://cvebrief.com/cve/cve-2025-6523/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2025-6523</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 23 Jul 2025 12:00:00 GMT</pubDate>
      <description>Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-6741 · CVSS 7.7 · Server</title>
      <link>https://cvebrief.com/cve/cve-2025-6741/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-devolutions-CVE-2025-6741</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/devolutions.png" medium="image" type="image/png"/>
      <pubDate>Wed, 23 Jul 2025 12:00:00 GMT</pubDate>
      <description>Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025 Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
