๐Ÿ” CVE Alert

CVE-2026-4434

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
1th

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

CWE CWE-295
Vendor devolutions
Product server
Published Mar 20, 2026
Last Updated Mar 23, 2026
Stay Ahead of the Next One

Get instant alerts for devolutions server

Be the first to know when new high vulnerabilities affecting devolutions server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Devolutions / Server
0 < 2026.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
devolutions.net: https://devolutions.net/security/advisories/DEVO-2026-0005/