CVE-2026-13327

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.

  • Published Sep 15, 2026
  • CVSS 8.3 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-13327 at the National Vulnerability Database