๐Ÿ” CVE Alert

CVE-2026-4396

HIGH 8.3
CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

CWE CWE-295
Vendor devolutions
Product hub reporting service
Published Mar 18, 2026
Last Updated Mar 18, 2026
Stay Ahead of the Next One

Get instant alerts for devolutions hub reporting service

Be the first to know when new high vulnerabilities affecting devolutions hub reporting service are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Devolutions / Hub Reporting Service
0 โ‰ค 2025.3.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
devolutions.net: https://devolutions.net/security/advisories/DEVO-2026-0009/