CVE Tools

Devolutions

133 CVEs tracked since 2021. Since Apr 2021, none of them reached CISA KEV.

Devolutions CVEs per month

Apr 2021 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Devolutions CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0480
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-0630
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-1230
2023-01null or fewer
2023-0240
2023-03null or fewer
2023-0450
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-1140
2023-1240
2024-01null or fewer
2024-02null or fewer
2024-0380
2024-04null or fewer
2024-05null or fewer
2024-0640
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-1150
2024-1240
2025-01null or fewer
2025-02null or fewer
2025-03100
2025-04null or fewer
2025-0550
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-1160
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-0390
2026-0480
2026-05140
2026-06150
2026-07140

Products

The products that kept showing up in Devolutions's monthly top three, with their CVEs summed over those months.

  1. Devolutions Server6716 months
  2. Server6512 months
  3. Remote Desktop Manager3413 months
  4. Powershell Universal72 months
  5. Workspace33 months
  6. Dvls (Devolutions Server)11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Devolutions.

  1. CVE-2026-92237Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to ...6.5
  2. CVE-2026-13327Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service ...8.3
  3. CVE-2026-84850Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to inter...4.8
  4. CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwor...6.5
  5. CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials a...6.5
  6. CVE-2026-78417Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept ...4.3
  7. CVE-2026-19768Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management perm...8.1
  8. CVE-2026-8497Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker t...7.4
  9. CVE-2026-17570Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. T...4.3
  10. CVE-2026-17569Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection e...4.3
  11. CVE-2026-17568Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to e...8.8
  12. CVE-2026-16802Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via s...6.5
  13. CVE-2026-16801Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permissi...8.8
  14. CVE-2026-16800Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permis...8.8
  15. CVE-2026-16799Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute aut...5.0

The record

Peak rank
#61 in Apr 2021
Busiest month shown
Jun 2026, 15 CVEs
Months with a KEV entry
0 since Apr 2021
Monthly snapshots
19 since 2021
Devolutions's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store