MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0032

Remote Desktop Manager macOS is affected by an Improper validation of certificate with host mismatch in CyberArk PKI authentication vulnerability.

Affected Products

Remote Desktop Manager
macOS2026.1.10.3 through 2026.1.24.0

Change Log

Initial publication - 2026-09-15

Improper validation of certificate with host mismatch in CyberArk PKI authentication

7.6 High - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Improper certificate validation with host mismatch in the CyberArk PKI authentication feature in Devolutions Remote Desktop Manager macOS 2026.1.10.3 through 2026.1.24.0 allows a man-in-the-middle attacker to intercept and tamper with CyberArk authentication traffic via a TLS certificate that chains to a trusted root but is issued for a different hostname.

CVE(s)

CVE-2026-92246

Remediation and Workarounds

Upgrade to Remote Desktop Manager macOS 2026.2.5.0 or higher.