Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
KEV
2026-05-07
Ivanti EPMM allows remote code execution for authenticated admins via improper input validation.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#supply-chain
Exploited
⌖ KEV
⚡ RCE
KEV
2026-05-06
Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#data-breach#default-creds
Exploited
⌖ KEV
⚡ RCE
KEV
2026-04-28
Microsoft Windows Shell allows network spoofing via a protection mechanism failure, enabling attackers to bypass authentication and execute commands.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-04-20
Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing local attackers to escalate privileges by reading credential files.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#default-creds#hardcoded-creds#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2026-04-20
Cisco Catalyst SD-WAN Manager allows remote attackers to view sensitive information due to an exposure vulnerability actively exploited in the wild.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
KEV
2026-04-20
Cisco Catalyst SD-WAN Manager allows attackers to overwrite arbitrary files and gain vmanage privileges via local file upload.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#privilege-escalation#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-04-14
Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#data-breach#unpatched
Exploited
⌖ KEV
KEV
2026-04-14
Microsoft SharePoint Server is actively exploited via CVE-2026-32201, enabling network spoofing that threatens DIB data integrity and trust.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#supply-chain#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2026-04-13
Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2026-04-13
Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2026-04-13
Microsoft VBA allows remote code execution via insecure library loading, actively exploited and linked to ransomware.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#unpatched
Exploited
⌖ KEV
KEV
2026-04-13
Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#privilege-escalation#supply-chain
Exploited
⌖ KEV
KEV
2026-04-13
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability enabling privilege escalation.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-04-08
Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain
Exploited
⌖ KEV
⚡ RCE
KEV
2026-04-01
Google Dawn (Chrome/Edge/Opera) use-after-free vulnerability enables remote code execution via crafted HTML.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain
Exploited
⌖ KEV
KEV
2026-03-30
Citrix NetScaler SAML IDP configuration allows out-of-bounds memory reads, enabling attackers to read sensitive data without code execution.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2026-03-18
Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited
⌖ KEV
KEV
2026-03-13
Google Skia contains an actively exploited out-of-bounds write vulnerability enabling remote memory access via crafted HTML.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#ransomware#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-03-13
Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#data-breach#unpatched
Exploited
⌖ KEV
KEV
2026-03-09
Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#auth-bypass#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-03-03
Broadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations.
AFFECTS 4
ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-25
Cisco's SD-WAN devices had an unpatched authentication bypass flaw allowing remote attackers to gain admin access.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-25
Cisco SD-WAN CLI exposed to path traversal, allowing local attackers to escalate privileges and execute commands as root.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-17
CVE-2008-0015: RCE in Windows Video ActiveX Control exploited in the wild
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-17
Chrome rce due to CSS use-after-free
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-12
Unauthenticated attacker exploited CVE-2024-43468 in Microsoft Configuration Manager, allowing SQL command execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-10
Authorized attacker could elevate privileges in Microsoft Office Word due to reliance on untrusted inputs
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-10
Microsoft Windows Shell Protection Mechanism Vulnerability actively exploited
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-10
Authorized attackers could elevate privileges locally in Microsoft Windows due to an improper privilege management vulnerability.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-10
Authorized attackers could elevate privileges on Windows systems due to a local type confusion vulnerability.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-02-10
Microsoft's MSHTML Framework allowed unauthorized attackers to bypass security features over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-02-10
Microsoft Windows exposed to remote denial of service via NULL pointer dereference
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-01-29
Ivanti EPMM exposed to unauthenticated RCE due to code injection flaw
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-01-26
Microsoft Office flaw exploited, users advised to transition to supported versions.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-01-23
Broadcom's VMware vCenter Server exploited for RCE due to unpatched out-of-bounds write in DCERPC protocol
AFFECTS 4
ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-01-21
Cisco UC products allow remote code execution.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild
Exploited
⌖ KEV
KEV
2026-01-13
Authorized attackers can disclose information on Windows systems due to an unpatched vulnerability.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-01-07
Microsoft Office PowerPoint allowed remote code execution through a vulnerability in its software.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2025-12-29
MongoDB exposed uninitialized heap memory through Zlib protocol headers
AFFECTS 1
MongoDB Atlas for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2025-12-17
Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched