Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2024-01-10
Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-01-10
An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation#auth-bypass#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2024-01-08
Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-01-08
Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2023-12-07
Qlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.
AFFECTS 1
Qlik Cloud Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2023-12-07
Qlik Sense path traversal flaw lets unauthenticated attackers create anonymous sessions to hit unauthorized endpoints.
AFFECTS 1
Qlik Cloud Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
◐ 0-DAY
KEV
2023-10-18
Citrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#supply-chain
Exploited
⌖ KEV
KEV
2023-09-13
Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2023-08-22
Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#auth-bypass
Exploited
⌖ KEV
KEV
2023-07-25
Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2023-07-19
Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2023-07-17
A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
◐ 0-DAY
KEV
2023-04-11
An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2023-04-07
An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2023-03-14
An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#initial-access
Exploited
⌖ KEV
⚡ RCE
KEV
2023-02-21
A YAML deserialization flaw in IBM Aspera Faspex allowed remote attackers to execute code, leading to ransomware-linked incidents.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2023-02-14
An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2023-02-02
An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2023-01-10
Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched#privilege-escalation#negligence
Exploited
⌖ KEV
KEV
2022-12-13
A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-11-08
An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-11-08
An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-10-24
Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-10-24
Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-09-30
Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-09-30
Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2022-06-14
An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-05-25
Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication by exploiting incomplete access control on non-GET/POST HTTP methods.
AFFECTS 1
Red Hat OpenShift Service on AWS (ROSA)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-05-25
Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-05-25
IBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-05-25
Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-05-25
A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-05-25
Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-05-25
A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-05-25
An incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST.
AFFECTS 1
Red Hat OpenShift Service on AWS (ROSA)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
KEV
2022-05-24
A Microsoft Internet Explorer/Edge vulnerability allowed attackers to detect files on user systems, linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
KEV
2022-05-24
Microsoft's SMBv1 vulnerability (CVE-2017-0147) allowed attackers to steal sensitive data from Windows processes via crafted packets, and was actively exploited in ransomware attacks, demonstrating a critical failure to secure a core Windows component.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-05-23
A Microsoft Windows vulnerability allowed privilege escalation via improper hard link handling, actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-05-23
A Microsoft Windows vulnerability allowed privilege escalation via improper privilege management in AppX deployments, actively exploited and linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-05-23
A Microsoft component, Update Notification Manager, had a privilege escalation vulnerability actively exploited in ransomware attacks, allowing attackers to gain elevated system access.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild