在 Devolutions Server 2026.2.16 及更早版本中,用于同步和集成功能的共享 HTTP 客户端存在不当的证书验证问题,使得处于网络中的攻击者能够通过伪造或自签名的证书,截获并篡改出站 TLS 连接。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | ≤ 2026.2.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Devolutions | Server | 0 ~ 2026.2.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13327 | Devolutions Server 2.16及以前LDAPS证书验证漏洞 | |
| CVE-2026-90969 | Devolutions Server 2026.2.16 访问控制缺陷泄露明文密码 | |
| CVE-2026-90971 | Devolutions Server 2026.2.16 SSRF漏洞 | |
| CVE-2026-92237 | Devolutions PowerShell Universal 慢查询日志敏感信息泄露 |
No comments yet