SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-8497

HIGH · CVSS 7.4 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Improper certificate validation in Devolutions Password Manager versions 2026.2.1.0 and earlier on Android, iOS, and macOS exposes users to the risk of adjacent-network attackers intercepting and altering sensitive information through forged TLS certificates. This vulnerability has a high severity rating and should be prioritized by organizations using Devolutions Password Manager to safeguard against potential data breaches and ensure secure communications.

CVE
CVE-2026-8497
Severity
HIGH
CVSS
7.4
EPSS
0.08%
Android

Original NVD Description

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.

Related CVEs

Other vulnerabilities affecting the same vendor(s)