CVE-2026-13327: Devolutions Devolutions Server vulnerability
Published Sep 15, 2026
·Updated
Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.
Affected Software
1 affected component
Devolutions Devolutions Server<=2026.2.16
Event History
Sep 15, 2026
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Devolutions Server deployments that connect to Active Directory over LDAPS are affected. The exposure concerns privileged directory service credentials used for those connections.
2
What capabilities does an attacker need to exploit this issue?
The attacker must be positioned on the network path for the LDAPS connection and able to present a spoofed domain controller certificate.
3
Which versions require remediation?
Devolutions Server version 2026.2.16 and earlier are affected.