CVE-2026-4434: Devolutions Server
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
Affected products
- Devolutions Devolutions Server: before 2026.1.6.0 (fixed in 2026.1.6.0)
Published 2026-03-20. Last modified 2026-06-17.