🔐 CVE Alert

CVE-2026-13327

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.

CWE CWE-295
Vendor devolutions
Product server
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for devolutions server

Be the first to know when new unknown vulnerabilities affecting devolutions server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Devolutions / Server
0 ≤ 2026.2.16

References

NVD ↗ CVE.org ↗ EPSS Data ↗
devolutions.net: https://devolutions.net/security/advisories/DEVO-2026-0030/