CVE-2026-4434: High severity Microsoft Windows Remote Management (WinRM) vulnerability
Published Mar 20, 2026
·Updated
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
Affected Software
2 affected components
Microsoft Windows Remote Management (WinRM)
Devolutions Devolutions Server<2026.1.6.0
Event History
Mar 20, 2026
CVE Published
via MITRE·12:52 PM
Data Sourced
via MITRE·12:52 PM
DescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 1, 58216
Event
via FIRST·01:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-4434?
CVE-2026-4434 has a critical severity rating due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2026-4434?
To fix CVE-2026-4434, ensure TLS certificate verification is enabled in your WinRM configuration.
3
What systems are affected by CVE-2026-4434?
CVE-2026-4434 affects Microsoft Windows Remote Management (WinRM) installations.
4
What is the impact of CVE-2026-4434?
The impact of CVE-2026-4434 includes the risk of unauthorized data interception by a network attacker.
5
Can CVE-2026-4434 be exploited remotely?
Yes, CVE-2026-4434 can be exploited by attackers remotely if proper certificate validation is not enforced.