CVE-2026-4434: Devolutions Server

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

Affected products

  • Devolutions Devolutions Server: before 2026.1.6.0 (fixed in 2026.1.6.0)

Published 2026-03-20. Last modified 2026-06-17.