CVE-2026-78417
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
| CWE | CWE-345 |
| Vendor | devolutions |
| Product | remote desktop manager |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for devolutions remote desktop manager
Be the first to know when new unknown vulnerabilities affecting devolutions remote desktop manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Devolutions / Remote Desktop Manager
0 < 2026.2.18
Devolutions / Remote Desktop Manager
0 < 2026.1.25