Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0029
Remote Desktop Manager is affected by an insufficient verification of data authenticity vulnerability.
Affected Products
Change Log
Initial publication - 2026-08-24
IronVNC auto-accepts untrusted VNC server RSA keys during RSA-AES authentication
7.1 High - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:L/SA:N
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
CVE(s)
CVE-2026-78417
Remediation and Workarounds
Upgrade to Devolutions Remote Desktop Manager 2026.2.18.0 or 2026.1.25.0 or higher.