VulnSea

devolutions has 11 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-295 (3). Most affected products: Server (4), devolutions_server (4), PowerShell Universal (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
11 prev 0

Products

  • Server 4
  • devolutions_server 4
  • PowerShell Universal 1
  • password_manager 1
  • powershell_universal 1
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

devolutions vulnerabilities

CVEs affecting devolutions, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-92237Medium· 6.5
1w ago

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protecti…

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protecti…

SunlitDevolutions · PowerShell UniversalEPSS 0.27%via NVD
CVE-2026-13327High· 8.3
1w ago

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

TwilightDevolutions · ServerEPSS 0.13%via NVD
CVE-2026-90971Medium· 6.5
1w ago

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata netwo…

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata netwo…

SunlitDevolutions · ServerEPSS 0.21%via NVD
CVE-2026-90969Medium· 6.5
1w ago

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing end…

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing end…

SunlitDevolutions · ServerEPSS 0.21%via NVD
CVE-2026-84850Medium· 4.8
1w ago

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connect…

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connect…

SunlitDevolutions · ServerEPSS 0.10%via NVD
CVE-2026-8497High· 7.4
1mo ago

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive informa…

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive informa…

Twilightdevolutions · password_managerEPSS 0.08%via NVD
CVE-2026-15641High· 7.1
2mo ago

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpo…

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpo…

Twilightdevolutions · devolutions_serverEPSS 0.29%via NVD
CVE-2026-15637High· 7.5
2mo ago

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credenti…

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credenti…

Twilightdevolutions · devolutions_serverEPSS 0.25%via NVD
CVE-2026-15058Low· 3.1
2mo ago

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

Sunlitdevolutions · devolutions_serverEPSS 0.21%via NVD
CVE-2026-13437Medium· 6.5
2mo ago

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authenticatio…

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authenticatio…

Sunlitdevolutions · powershell_universalEPSS 0.44%via NVD
CVE-2026-12755Low· 2.7
2mo ago

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-contro…

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-contro…

Sunlitdevolutions · devolutions_serverEPSS 0.36%via NVD
devolutions vulnerabilities (CVEs) · VulnSea