CVE-2026-84850: Devolutions Devolutions Server 2026.2.16 vulnerability
Published Sep 15, 2026
·Updated
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
Affected Software
1 affected component
Devolutions Devolutions Server 2026.2.16<=2026.2.16
Event History
Sep 15, 2026
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Prioritize Devolutions Server deployments running version 2026.2.16 or earlier that use synchronization or integration features, because those features use the affected shared HTTP client. The provided information does not identify other affected connection paths.
2
What access does an attacker need to exploit this issue?
The attacker must be positioned on the network path for outbound TLS connections. The provided information does not state whether any authenticated access to Devolutions Server is required.