Devolutions Server
Vendor:
First CVE: Apr 1, 2021 · Active for 5 years
109
Total CVEs
More Total CVEs than 99% of tracked products
18.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Devolutions Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2021
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Devolutions Server109 CVEs
10%
58%
27%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.8%)
Network105 (96.3%)
Unknown0 (0.0%)
Physical1 (0.9%)
Adjacent Network1 (0.9%)
Attack Complexity
Low93 (85.3%)
High16 (14.7%)
Unknown0 (0.0%)
User Interaction
None98 (89.9%)
Unknown0 (0.0%)
Required11 (10.1%)
Privileges Required
Low75 (68.8%)
High10 (9.2%)
None24 (22.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (109 CVEs).
109 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14536HIGH Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required po | Jul 6, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-0610CRITICAL SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12 | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-9047HIGH Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass t | May 22, 2026 | 7.6 | 32 | NO | NO |
CVE-2026-15641HIGH Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending acc | Jul 14, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-3224CRITICAL Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an ar | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-3204CRITICAL Improper
input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafte | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-3130CRITICAL Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is | Mar 3, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-13757HIGH SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8. | Nov 27, 2025 | 8.8 | 31 | NO | NO |
CVE-2026-15637HIGH Improper authorization in the PAM SSH key and certificate retrieval
endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an
authenticated low-privileged user to disclose t | Jul 14, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-12485HIGH Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MF | Nov 6, 2025 | 8.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (109 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (109 CVEs).
Media Mentions
Signals from CVEs in this product scope (109 CVEs).
Top CNAs Publishing CVEs For Devolutions Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2026.2.4.0 | 3 | 5.8 | 0.2% | 0 | 0 |