Improper Certificate Validation in Devolutions Server by Devolutions
CVE-2026-84850

Currently unrated

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-84850?

A vulnerability exists in Devolutions Server due to improper certificate validation within its shared HTTP client. This flaw allows a network-positioned attacker to create conditions for intercepting and tampering with outbound TLS connections utilizing spoofed or self-signed certificates. This could lead to a serious compromise of sensitive data in transit. Users of affected versions should consider evaluating their network's security posture to mitigate potential risks.

Affected Version(s)

Server 0 <= 2026.2.16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.