Powershell Universal
Vendor:
First CVE: Jan 7, 2026 · Active for under a year
11
Total CVEs
More Total CVEs than 89% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Powershell Universal over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 7, 2026
6 months ago
Most Recent CVE
Jul 24, 2026
1 day ago
CVE Severity & Scoring
Powershell Universal11 CVEs
73%
27%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low8 (72.7%)
High1 (9.1%)
None2 (18.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-16801HIGH Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variab | Jul 24, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-16800HIGH Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedul | Jul 24, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-13437MEDIUM Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obt | Jun 29, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-4064HIGH Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based acces | Mar 17, 2026 | 8.3 | 29 | NO | NO |
CVE-2026-16802MEDIUM Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read se | Jul 24, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-16798MEDIUM Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job o | Jul 24, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-16799MEDIUM Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader ro | Jul 24, 2026 | 5.0 | 24 | NO | NO |
CVE-2026-8694MEDIUM Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST | Jun 12, 2026 | 5.3 | 22 | NO | NO |
CVE-2026-3277MEDIUM The OpenID Connect (OIDC) authentication configuration in PowerShell
Universal before 2026.1.3 stores the OIDC client secret in cleartext in
the .universal/authentication.ps1 scr | Feb 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-0618MEDIUM Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. | Jan 7, 2026 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Powershell Universal
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2026.2.0.0 | 1 | 6.5 | 0.3% | 0 | 0 |