CVE-2026-3204: Devolutions Server

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

Affected products

  • Devolutions Devolutions Server: up to and including 2025.3.16.0

Published 2026-03-03. Last modified 2026-06-17.