PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16800 Devolutions CVE debrief

CVE-2026-16800 is a high-severity vulnerability in Devolutions PowerShell Universal, allowing authenticated users with schedule creation permissions to inject arbitrary PowerShell code. This issue affects versions 2026.2.2 and earlier. The vulnerability exists in the schedule feature, where an authenticated user can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenated into a script invocation. Users of Devolutions PowerShell Universal should apply patches to prevent code injection attacks and review system configurations for potential exposure.

Vendor
Devolutions
Product
PowerShell Universal
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-07-27
Advisory published
2026-07-24
Advisory updated
2026-07-27

Who should care

Users of Devolutions PowerShell Universal 2026.2.2 and prior should apply patches to prevent code injection attacks. System administrators, security teams, and operators responsible for managing Devolutions PowerShell Universal deployments should review system configurations, verify patch compliance, and monitor for suspicious activity. Additionally, security teams should review compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

The vulnerability exists in the schedule feature of Devolutions PowerShell Universal. An authenticated user with schedule creation permission can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenated into a script invocation. This issue affects versions 2026.2.2 and earlier. The vulnerability has a high CVSS score of 8.8, indicating a high severity. Defenders should prioritize patching and review system configurations for potential exposure.

Defensive priority

High priority due to high CVSS score of 8.8 and potential for code injection.

Recommended defensive actions

  • Apply patches from Devolutions
  • Restrict schedule creation permissions
  • Monitor for suspicious schedule creations
  • Inventory and update affected systems
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence from NVD and CVE.org indicates a high-severity vulnerability exists in Devolutions PowerShell Universal. Limited details are available on affected scope, including specific versions and configurations, and vendor remediation efforts. Defenders should verify system configurations, review logs for suspicious activity, and monitor for updates from Devolutions. The CVE record was published on 2026-07-24T15:17:12.963Z and has not been modified since then.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:17:12.963Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.