CVE-2026-8497: Devolutions Password Manager
High severity, CVSS 7.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
Affected products
- Devolutions Password Manager: before 2026.2.2.0 (fixed in 2026.2.2.0)
Published 2026-07-29. Last modified 2026-08-21.