Devolutions disclosed five vulnerabilities in PowerShell Universal 2026.2.2 and earlier, including two high-severity code injection flaws and multiple secret-handling weaknesses, all fixed in version 2026.2.3. The most serious issue, CVE-2026-16801, allows an authenticated user with variable write permission to inject arbitrary PowerShell code because user-supplied values are not properly escaped when written to the variables configuration file. A related flaw, CVE-2026-16800, affects the schedule feature, while Devolutions also reported improper access control issues in automation tests and workflows and exposure of stored OAuth refresh tokens.
A separate weakness, CVE-2026-16802, stores secret-type variables in plaintext on disk when no external vault is configured, exposing API keys, database connection strings, service account credentials, and other sensitive tokens to anyone with local read access. CERT Uganda warned that the code injection bugs could run with the privileges of the PowerShell Universal service account—often highly privileged on Windows Server—creating a path to full host compromise, data theft, lateral movement, and persistence. Organizations were urged to upgrade to PowerShell Universal 2026.2.3, audit variable and schedule configurations, review service account privileges, configure an external vault such as HashiCorp Vault, Azure Key Vault, or Windows DPAPI, and rotate any credentials that may have been exposed.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Devolutions stated in the advisory that the disclosed PowerShell Universal vulnerabilities are fixed in version 2026.2.3 or later, and affected organizations were advised to upgrade.
On July 24, 2026, Devolutions disclosed advisory DEVO-2026-0025 covering five vulnerabilities affecting PowerShell Universal 2026.2.2 and earlier, including code injection, cleartext secret storage, OAuth refresh token exposure, and improper access control issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcecert.ug
Open sourcedevolutions.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.