CVE-2026-4434Disclosure(devolutions / devolutions_server)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • devolutions_server

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
devolutions_server

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Mentions · 2026-05-03: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 1Technical Details · 2026-05-03: 103-2203-2305-03
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-231
Disclosure1
2026-05-031
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4434 Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate … https://www.cve.org/CVERecord?id=CVE-2026-4434

    Post summary

    The post announces CVE‑2026‑4434, noting that improper certificate validation in PAM‑propagated WinRM connections can lead to man‑in‑the‑middle attacks via disabled TLS certificates, with no evidence of exploitation or mitigation mentioned.

    0001082
    56.8K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    General

    CVE-2026-4434: TLS verification disabled in PAM over WinRM. Network-adjacent attacker can MitM auth traffic, steal creds, pivot. #infosec #CVE #cybersecurity #devops #devsecops #100daysofcybersecurity info: https://www.valtersit.com/cve/2026/03/cve-2026-4434/

    Post summary

    The post briefly outlines CVE-2026-4434, highlighting insecure TLS verification in PAM over WinRM that allows MitM attackers to steal credentials, with no evidence of an exploit, patch, or active exploitation.

    0000072
    889 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4434 - High Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. https://www.thehackerwire.com/vulnerability/CVE-2026-4434/ https://t.co/KbXUuR5juz

    Post summary

    The brief notice announces CVE‑2026‑4434 as a certificate validation flaw in Windows PAM propagation WinRM that could enable man‑in‑the‑middle attacks when TLS verification is disabled.

    0000034
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdevolutionsdevolutions_server---

Explore more