SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78417

MEDIUM · CVSS 4.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The IronVNC client in Devolutions Remote Desktop Manager versions 2026.2.17.0 and earlier is vulnerable due to insufficient verification of data authenticity, allowing on-path attackers to intercept and manipulate VNC sessions by automatically accepting the server's RSA key during authentication. This vulnerability poses a significant risk to the confidentiality and integrity of remote desktop communications. Organizations using affected versions should prioritize remediation to safeguard against potential session hijacking and data tampering.

CVE
CVE-2026-78417
Severity
MEDIUM
CVSS
4.3
EPSS
0.11%

Original NVD Description

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.