Devolutions Inc.
First CVE: Oct 18, 2021Active for: 5 years
160
CVEs Published
More CVEs Published than 76% of tracked CNAs
26.7
Avg CVEs / Year
More Avg CVEs / Year than 75% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 18% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Devolutions Inc. as a CNA, 99.4% affect products that Devolutions Inc. develops as a vendor.
99.4%
Self-reported: 159Third-party: 1
Of all the CVEs published that affect products developed by Devolutions Inc., 91.9% are self-published by Devolutions Inc. as a CNA.
91.9%
Self-published: 159Published by other CNAs: 14
Trends Over Time
The number and severity of CVEs published by Devolutions Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2021
4 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by Devolutions Inc. as a CNA, regardless of affected vendor or product.
160 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12161HIGH Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a | Jun 16, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-14536HIGH Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required po | Jul 6, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-0610CRITICAL SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12 | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-13372HIGH Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with | Jun 26, 2026 | 7.2 | 33 | NO | NO |
CVE-2026-10696HIGH Use of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community
catalog contributor to cause an inst | Jun 17, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-9047HIGH Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass t | May 22, 2026 | 7.6 | 32 | NO | NO |
CVE-2026-15641HIGH Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending acc | Jul 14, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-13437MEDIUM Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obt | Jun 29, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-3224CRITICAL Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an ar | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-3204CRITICAL Improper
input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafte | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA160 CVEs
8%
57%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (6.9%)
Network146 (91.3%)
Unknown0 (0.0%)
Physical2 (1.3%)
Adjacent Network1 (0.6%)
Attack Complexity
Low140 (87.5%)
High20 (12.5%)
Unknown0 (0.0%)
User Interaction
None142 (88.8%)
Unknown0 (0.0%)
Required18 (11.3%)
Privileges Required
Low108 (67.5%)
High13 (8.1%)
None39 (24.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (160 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Devolutions Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Devolutions Inc. as a CNA — matched by CVE ID, not by organization name.