HIGHCVSS 7.4Vulnerability

CVE-2026-8497

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.

Properties

severity
HIGH
cvss_score
7.4
cvss_severity
HIGH
epss_score
0.00132
retrieved_at
2026-10-04T19:49:43+00:00
last_source
FIRST EPSS
score
7.4
cve_id
CVE-2026-8497
cvss_vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-11T17:55:57+00:00
vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
published_at
2026-07-29T18:16:58.787
last_modified
2026-08-21T15:07:40.067
epss_percentile
0.02328

Related Entities (7)

ENRICHED_BY (1)

→[Source]FIRST EPSS

AFFECTS_PRODUCT (4)

→[Product]
→[Product]
→[Product]
→[Product]

HAS_WEAKNESS (1)

→[Weakness]Improper Certificate Validation

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph