Devolutions Server

Vendor:

First CVE: Apr 1, 2021 · Active for 5 years

109
Total CVEs
More Total CVEs than 99% of tracked products
18.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Devolutions Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2021
5 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Devolutions Server109 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (1.8%)
Network105 (96.3%)
Unknown0 (0.0%)
Physical1 (0.9%)
Adjacent Network1 (0.9%)
Attack Complexity
Low93 (85.3%)
High16 (14.7%)
Unknown0 (0.0%)
User Interaction
None98 (89.9%)
Unknown0 (0.0%)
Required11 (10.1%)
Privileges Required
Low75 (68.8%)
High10 (9.2%)
None24 (22.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (109 CVEs).

109 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required po
Jul 6, 20268.835NONO
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
Jan 19, 20269.834NONO
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass t
May 22, 20267.632NONO
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending acc
Jul 14, 20267.131NONO
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an ar
Mar 3, 20269.831NONO
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafte
Mar 3, 20269.831NONO
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is
Mar 3, 20269.831NONO
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.
Nov 27, 20258.831NONO
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose t
Jul 14, 20267.530NONO
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MF
Nov 6, 20258.830NONO

Exploit Exposure

Signals from CVEs in this product scope (109 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (109 CVEs).

Media Mentions

Signals from CVEs in this product scope (109 CVEs).

Top CNAs Publishing CVEs For Devolutions Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2026.2.4.035.80.2%00