SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-84850

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a…

UnscoredEPSS —

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.

CVSS
Not yet scored
EPSS
No score yet
CISA KEV
Not listed
Weakness
CWE-295
Source
security@devolutions.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.