Devolutions vulnerabilities
10 CVEs tracked
Devolutions appears in recent reports with multiple critical vulnerabilities across its product suite. The primary concerns in PowerShell Universal are code injection flaws (CVE-2026-16800, CVE-2026-16801) exploitable by authenticated users, and the exposure of sensitive information like OAuth tokens and cleartext secrets (CVE-2026-16798, CVE-2026-16802). Additionally, Devolutions Server is affected by access control issues enabling privilege escalation (CVE-2026-17568) and disclosure of PAM password history (CVE-2026-17570). Defenders should prioritize applying the updates for PowerShell Universal, strictly audit permissions on the 'Variables' and 'Schedule' features, and review API access controls in Devolutions Server.
Azərbaycanca: Devolutions, son hesabat dövründə məhsullarında aşkarlanan çoxsaylı kritik boşluqlarla diqqət mərkəzindədir. Əsas problemlər PowerShell Universal-da autentifikasiya olunmuş istifadəçilər tərəfindən kod inyeksiyasına (CVE-2026-16800, CVE-2026-16801) və həssas məlumatların (OAuth token, sirli dəyişənlər) ifşa olunmasına (CVE-2026-16798, CVE-2026-16802) imkan verən zəifliklərdir. Eyni zamanda, Devolutions Server-də imtiyazların yüksəldilməsinə (CVE-2026-17568) və PAM şifrə tarixçəsinin oxunmasına (CVE-2026-17570) səbəb olan giriş nəzarəti problemləri mövcuddur. Müdafiəçilər PowerShell Universal üçün dərc olunmuş yeniləmələri tətbiq etməyə, xüsusilə 'Variables' və 'Schedule' funksiyaları üzərində icazələri sıx şəkildə nəzərdən keçirməyə və Devolutions Server-də API giriş nəzarəti mexanizmlərini yoxlamağa diqqət yetirməlidir.
This vendor's CVEs10
This hub is built from skopnix's own reporting on Devolutions: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.