SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13327

UNKNOWN · CVSS N/A EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Devolutions Server versions 2026.2.16 and earlier are vulnerable due to improper certificate validation on LDAPS connections to Active Directory, enabling an attacker with network access to intercept privileged directory service credentials by presenting a spoofed domain controller certificate. Organizations using these versions should prioritize remediation to mitigate the risk of credential theft and potential unauthorized access to sensitive directory services.

CVE
CVE-2026-13327
Severity
UNKNOWN
CVSS
N/A
EPSS
0.12%

Original NVD Description

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.