MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0029

Remote Desktop Manager is affected by an insufficient verification of data authenticity vulnerability.

Affected Products

Remote Desktop Manager
Windows2026.2.17.0 and earlier
Windows2026.1.24.0 and earlier

Change Log

Initial publication - 2026-08-24

IronVNC auto-accepts untrusted VNC server RSA keys during RSA-AES authentication

7.1 High - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:L/SA:N

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.

CVE(s)

CVE-2026-78417

Remediation and Workarounds

Upgrade to Devolutions Remote Desktop Manager 2026.2.18.0 or 2026.1.25.0 or higher.