Security Advisory

CVE-2026-8497

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-29 17:24:59
Last updated 2026-07-29 18:14:01
Assigner DEVOLUTIONS
CVSS score not scored
State PUBLISHED

Description

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.