Devolutions Powershell Universal — known CVE vulnerabilities
Every CVE whose affected-product data names Devolutions Powershell Universal, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2026-16800 — CVSS 8.8 (high): Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier…
CVE-2026-16801 — CVSS 8.8 (high): Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier…
CVE-2026-13437 — CVSS 6.5 (medium): Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an…
CVE-2026-16798 — CVSS 6.5 (medium): Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier…
CVE-2026-16802 — CVSS 6.5 (medium): Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local…
CVE-2026-16799 — CVSS 5.0 (medium): Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an…