VulnerabilityReceived
CVE-2026-84850
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a…
UnscoredEPSS —
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
- CVSS
- Not yet scored
- EPSS
- No score yet
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Source
- security@devolutions.net
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.