Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Devolutions Inc.

First CVE: Jan 26, 2021Active for: 5 yearsTotal CVEs: 173
26.4
VTI Score
Low

Devolutions Inc. develops a narrow but strategically positioned suite of credential management, remote-access, and workspace-orchestration products, including Devolutions Server, Remote Desktop Manager, and Devolutions Gateway, that are widely deployed in enterprise environments to centralize access control and identity governance. Vulnerabilities affecting the vendor concentrate in access-control and authorization mechanisms—including improper access control, incorrect authorization logic, and exposure of sensitive credentials—reflecting the security-critical role these products play in managing privileged accounts and remote sessions. A meaningful share of the vendor's disclosures reach serious severity, though the exposure pattern centers on authentication and data-protection flaws rather than memory corruption or network-layer weaknesses. Defenders should treat this vendor's advisories as priority in identity-and-access tiers and ensure timely remediation of credential-management infrastructure; live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
173
Total CVEs
More Total CVEs than 100% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Devolutions Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2021
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Self-Reporting Analysis

Of all the CVEs published by Devolutions Inc. as a CNA, 99.4% affect products that Devolutions Inc. develops as a vendor.

99.4%
Self-reported: 159 (99.4%)
Third-party: 1 (0.6%)

Of all the CVEs published that affect products developed by Devolutions Inc., 91.9% are self-published by Devolutions Inc. as a CNA.

91.9%
Self-published: 159 (91.9%)
Other CNAs: 14 (8.1%)

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (173 CVEs).

173 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-12161HIGH
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a
Jun 16, 20268.837NONO
CVE-2026-14536HIGH
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required po
Jul 6, 20268.835NONO
CVE-2026-0610CRITICAL
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
Jan 19, 20269.834NONO
CVE-2026-13372HIGH
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with
Jun 26, 20267.233NONO
CVE-2026-10696HIGH
Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an inst
Jun 17, 20267.532NONO
CVE-2026-9047HIGH
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass t
May 22, 20267.632NONO
CVE-2026-15641HIGH
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending acc
Jul 14, 20267.131NONO
CVE-2026-13437MEDIUM
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obt
Jun 29, 20266.531NONO
CVE-2026-3224CRITICAL
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an ar
Mar 3, 20269.831NONO
CVE-2026-3204CRITICAL
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafte
Mar 3, 20269.831NONO
View all 173 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products173 CVEs
8%
55%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (6.4%)
Network158 (91.3%)
Unknown0 (0.0%)
Physical3 (1.7%)
Adjacent Network1 (0.6%)
Attack Complexity
Low151 (87.3%)
High22 (12.7%)
Unknown0 (0.0%)
User Interaction
None151 (87.3%)
Unknown0 (0.0%)
Required22 (12.7%)
Privileges Required
Low114 (65.9%)
High14 (8.1%)
None45 (26.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (173 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Devolutions Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Devolutions Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Devolutions Inc.'s Products

View all 2 CNAs →

Top CWEs