Devolutions Inc. develops a narrow but strategically positioned suite of credential management, remote-access, and workspace-orchestration products, including Devolutions Server, Remote Desktop Manager, and Devolutions Gateway, that are widely deployed in enterprise environments to centralize access control and identity governance. Vulnerabilities affecting the vendor concentrate in access-control and authorization mechanisms—including improper access control, incorrect authorization logic, and exposure of sensitive credentials—reflecting the security-critical role these products play in managing privileged accounts and remote sessions. A meaningful share of the vendor's disclosures reach serious severity, though the exposure pattern centers on authentication and data-protection flaws rather than memory corruption or network-layer weaknesses. Defenders should treat this vendor's advisories as priority in identity-and-access tiers and ensure timely remediation of credential-management infrastructure; live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devolutions Inc. over time
Of all the CVEs published by Devolutions Inc. as a CNA, 99.4% affect products that Devolutions Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Devolutions Inc., 91.9% are self-published by Devolutions Inc. as a CNA.
Signals from CVEs in this vendor scope (173 CVEs).
173 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12161HIGH Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a | Jun 16, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-14536HIGH Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required po | Jul 6, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-0610CRITICAL SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12 | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-13372HIGH Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with | Jun 26, 2026 | 7.2 | 33 | NO | NO |
CVE-2026-10696HIGH Use of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community
catalog contributor to cause an inst | Jun 17, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-9047HIGH Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass t | May 22, 2026 | 7.6 | 32 | NO | NO |
CVE-2026-15641HIGH Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending acc | Jul 14, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-13437MEDIUM Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obt | Jun 29, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-3224CRITICAL Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an ar | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-3204CRITICAL Improper
input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafte | Mar 3, 2026 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (173 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devolutions Inc..
Media articles that mention a CVE ID that affects a product developed by Devolutions Inc. — matched by CVE ID, not by vendor name.