Vulnerabilidades en Devolutions

176 resultados
Análisis Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2026-10787MEDIUMMissing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadataEPSS 0.2%CVE-2026-3221MEDIUMSensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker wEPSS 0.2%CVE-2026-15642LOWInsertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.EPSS 0.2%CVE-2024-7421MEDIUMAn information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to systeEPSS 0.2%CVE-2026-16799MEDIUMImproper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an auEPSS 0.2%CVE-2026-10786MEDIUMImproper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain clEPSS 0.1%CVE-2026-12162MEDIUMImproper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclosEPSS 0.1%CVE-2026-4396HIGHImproper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-EPSS 0.1%CVE-2026-4434HIGHImproper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack viEPSS 0.1%CVE-2024-11862MEDIUMNon constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption EPSS 0.1%CVE-2026-9522MEDIUMImproper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user withouEPSS 0.1%CVE-2026-13327HIGHImproper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positiEPSS 0.1%CVE-2026-78417MEDIUMInsufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.2EPSS 0.1%CVE-2026-84850MEDIUMImproper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 aEPSS 0.1%CVE-2026-8497HIGHImproper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on AndrEPSS 0.1%CVE-2026-16802MEDIUMCleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local EPSS 0.1%