CVE Tools

Devolutions Server

112 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Devolutions Server, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Devolutions Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Devolutions Server CVEs per month
MonthCVEs
2024-100
2024-111
2024-123
2025-010
2025-021
2025-034
2025-040
2025-054
2025-063
2025-074
2025-080
2025-090
2025-103
2025-116
2025-120
2026-012
2026-023
2026-035
2026-048
2026-0514
2026-069
2026-078
2026-080
2026-090

Severity

How the 112 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical65%
  • High3027%
  • Medium6558%
  • Low1110%

Latest CVEs

The 15 most recently published vulnerabilities affecting Devolutions Server.

  1. CVE-2026-17570Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. T...4.3
  2. CVE-2026-17569Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection e...4.3
  3. CVE-2026-17568Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to e...8.8
  4. CVE-2026-15058Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object referen...3.1
  5. CVE-2026-15642Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated re...3.3
  6. CVE-2026-15641Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a...7.1
  7. CVE-2026-15637Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of...7.5
  8. CVE-2026-14536Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenti...8.8
  9. CVE-2026-12755Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-si...2.7
  10. CVE-2026-12105Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.6.5
  11. CVE-2026-12117Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not ...4.3
  12. CVE-2026-11890Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.4.3
  13. CVE-2026-10544Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbit...6.5
  14. CVE-2026-10787Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This ...4.3
  15. CVE-2026-10786Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store