| CVE-2026-17568 | 8.8 | — | — | — | devolutions / devolutions server | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated n | 40d ago |
| CVE-2026-16801 | 8.8 | — | — | — | devolutions / powershell universal | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Unive | 43d ago |
| CVE-2026-16800 | 8.8 | — | — | — | devolutions / powershell universal | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Univer | 43d ago |
| CVE-2026-14536 | 8.8 | — | — | — | devolutions / devolutions server | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an | 61d ago |
| CVE-2026-12161 | 8.8 | — | — | — | devolutions / remote desktop manager | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create | 82d ago |
| CVE-2026-4434 | 8.1 | — | — | — | devolutions / devolutions server | Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man | 169d ago |
| CVE-2026-4396 | 8.1 | — | — | — | devolutions / hub reporting service | Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attack | 171d ago |
| CVE-2026-9047 | 7.6 | — | — | — | devolutions / devolutions server | Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server a | 106d ago |
| CVE-2026-15637 | 7.5 | — | — | — | devolutions / devolutions server | Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 202 | 53d ago |
| CVE-2026-10696 | 7.5 | — | — | — | devolutions / unigetui | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlie | 80d ago |
| CVE-2026-8497 | 7.4 | — | — | — | devolutions / password manager | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026. | 38d ago |
| CVE-2026-13372 | 7.2 | — | — | — | devolutions / remote desktop manager | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manage | 71d ago |
| CVE-2026-15641 | 7.1 | — | — | — | devolutions / devolutions server | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an | 53d ago |
| CVE-2026-7325 | 7.1 | — | — | — | devolutions / devolutions server | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authe | 106d ago |