CVE-2026-1007: Devolutions Server
High severity, CVSS 7.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.
Affected products
- Devolutions Devolutions Server: from 2025.3.1.0, before 2025.3.14.0 (fixed in 2025.3.14.0)
Published 2026-01-19. Last modified 2026-06-17.