Improper Certificate Validation in Devolutions Server Affects Active Directory Connections
CVE-2026-13327

Currently unrated

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-13327?

An improper certificate validation vulnerability has been identified in Devolutions Server, specifically impacting LDAPS connections to Active Directory. This flaw allows network-positioned attackers to intercept privileged directory service credentials through a spoofed domain controller certificate. Organizations using affected versions of Devolutions Server should prioritize evaluating their configurations to prevent exploitation and secure sensitive credential transmission.

Affected Version(s)

Server 0 <= 2026.2.16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.