CVE-2026-78417: Devolutions Remote Desktop Manager
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Affected products
- Devolutions Remote Desktop Manager: before 2026.2.18 (fixed in 2026.2.18); before 2026.1.25 (fixed in 2026.1.25)
Published 2026-08-24. Last modified 2026-08-28.