Server
This hub aggregates every CVE we track for Server, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
266
CVEs tracked
37
Critical
89
High
0
In CISA KEV
Severity distribution
MEDIUM109HIGH89CRITICAL37LOW25
Monthly trend
0
0
3
0
1
5
0
3
3
5
2
0
3
6
2
2
3
9
10
19
19
12
16
13
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Server.
- CVE-2026-58272Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)5.3
- CVE-2026-58270Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`6.5
- CVE-2026-58269Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`8.1
- CVE-2026-58271@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`6.8
- CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.6.5
- CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this re...6.2
- CVE-2026-82985The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration...6.5
- CVE-2026-68493After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.3.1
- CVE-2026-13327Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service ...8.3
- CVE-2026-84850Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to inter...4.8
- CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwor...6.5
- CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials a...6.5
- CVE-2026-54047Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation
- CVE-2026-82246Budibase Server before 3.41.3 SSRF via Query Import7.1
- CVE-2026-82245Budibase before 3.41.3 Missing Authorization License Management8.1
Product normalization is registry-driven with AI assist and human review. How it works