CVE-2026-12162: Devolutions Remote Desktop Manager

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Affected products

  • Devolutions Remote Desktop Manager: before 2026.2.9.0 (fixed in 2026.2.9.0)

Published 2026-06-16. Last modified 2026-06-17.