CVE-2026-3224Disclosure(devolutions / devolutions_server)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • devolutions_server

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-03); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
devolutions_server

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-03: 2Mentions · 2026-03-04: 2Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 203-0303-04
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3224 Microsoft Entra ID Authentication Bypass in Devolutions Server via... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3224 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post alerts readers to a Microsoft Entra ID authentication bypass vulnerability (CVE‑2026‑3224) and provides a link to detailed information, but offers no PoC, exploit, or patch details.

    0001048
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3224 - Critical Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary ... https://www.thehackerwire.com/vulnerability/CVE-2026-3224/ https://t.co/kBLTtXF0ZS

    Post summary

    The tweet announces a critical authentication bypass vulnerability in Devolutions Server, allowing unauthenticated users to log in as arbitrary accounts.

    0000071
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3224 Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authentic… https://www.cve.org/CVERecord?id=CVE-2026-3224 ----- Traducción: CVE-2026-3224, om… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-3224, an authentication bypass in Devolutions Server’s Azure AD mode, linking to the CVE record but providing no PoC, exploit, or patch details.

    0000033
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3224 Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authentic… https://www.cve.org/CVERecord?id=CVE-2026-3224

    Post summary

    The text announces CVE-2026-3224, an authentication bypass in Devolutions Server's Azure AD mode, affecting versions up to 2025.3.15.0, with no mention of PoC, exploit, or patch.

    00000283
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdevolutionsdevolutions_server---

Explore more