CVE-2026-8497
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
| CWE | CWE-295 |
| Vendor | devolutions |
| Product | password manager |
| Published | Jul 29, 2026 |
| Last Updated | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for devolutions password manager
Be the first to know when new high vulnerabilities affecting devolutions password manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Devolutions / Password Manager
0 < 2026.2.2