Devolutions
133 CVEs tracked since 2021. Since Apr 2021, none of them reached CISA KEV.
Devolutions CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-04 | 8 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | 3 | 0 |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | 3 | 0 |
| 2023-01 | null or fewer | |
| 2023-02 | 4 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 5 | 0 |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | 4 | 0 |
| 2023-12 | 4 | 0 |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | 8 | 0 |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | 4 | 0 |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | 5 | 0 |
| 2024-12 | 4 | 0 |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | 10 | 0 |
| 2025-04 | null or fewer | |
| 2025-05 | 5 | 0 |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | 6 | 0 |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | 9 | 0 |
| 2026-04 | 8 | 0 |
| 2026-05 | 14 | 0 |
| 2026-06 | 15 | 0 |
| 2026-07 | 14 | 0 |
Products
The products that kept showing up in Devolutions's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Devolutions.
- CVE-2026-92237Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to ...6.5
- CVE-2026-13327Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service ...8.3
- CVE-2026-84850Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to inter...4.8
- CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwor...6.5
- CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials a...6.5
- CVE-2026-78417Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept ...4.3
- CVE-2026-19768Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management perm...8.1
- CVE-2026-8497Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker t...7.4
- CVE-2026-17570Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. T...4.3
- CVE-2026-17569Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection e...4.3
- CVE-2026-17568Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to e...8.8
- CVE-2026-16802Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via s...6.5
- CVE-2026-16801Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permissi...8.8
- CVE-2026-16800Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permis...8.8
- CVE-2026-16799Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute aut...5.0
The record
- Peak rank
- #61 in Apr 2021
- Busiest month shown
- Jun 2026, 15 CVEs
- Months with a KEV entry
- 0 since Apr 2021
- Monthly snapshots
- 19 since 2021