SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84850

UNKNOWN · CVSS N/A EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Devolutions Server versions 2026.2.16 and earlier have a vulnerability in their shared HTTP client that improperly validates certificates, enabling attackers positioned on the network to intercept and manipulate outbound TLS connections using spoofed or self-signed certificates. Organizations utilizing Devolutions Server should prioritize addressing this issue to mitigate the risk of data interception and integrity compromise. Immediate action is recommended for those relying on synchronization and integration features within the affected software.

CVE
CVE-2026-84850
Severity
UNKNOWN
CVSS
N/A
EPSS
0.09%

Original NVD Description

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.