Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
KEV
2021-11-03
An unpatched privilege escalation flaw in Windows Update Medic Service was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2021-11-03
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
AFFECTS 2
Trend Micro Cloud One for GovernmentTrend Micro Vision One for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft MSCOMCTL.OCX contained a remote code execution vulnerability that allowed attackers to take full control of affected systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
AFFECTS 2
Trend Micro Cloud One for GovernmentTrend Micro Vision One for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
KEV
2021-11-03
A use-after-free flaw in Chromium's Indexed DB API allowed sandbox escapes after a renderer compromise, but required prior compromise and was not a zero-day.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
AFFECTS 2
SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild
Exploited
⌖ KEV
KEV
2021-11-03
Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability (CVE-2021-31199) was actively exploited in the wild, allowing attackers to escalate privileges on affected systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability (CVE-2021-31201) was actively exploited in the wild, allowing attackers to escalate privileges on affected systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
KEV
2021-11-03
An unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A remote code execution vulnerability in Microsoft Windows MSHTML was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
A privilege escalation flaw in Microsoft's Desktop Window Manager was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
An unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
An unpatched privilege escalation flaw in Windows NTFS allowed attackers to gain elevated access via a crafted application.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Critical
CVSS 10.0
NVD
2026-06-30
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.9
NVD
2026-07-06
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited pr
AFFECTS 1
Secure Remote Access
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-07-06
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, i
AFFECTS 1
Secure Remote Access
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AFFECTS 1
Citrix for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
⚡ RCE
◐ 0-DAY
CVSS 9.8
NVD
2026-06-30
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Remote code execution — patch the affected products on priority.
#rce#zero-day
Critical
CVSS 9.8
NVD
2026-06-30
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured
AFFECTS 1
Citrix for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
⚡ RCE
CVSS 9.8
NVD
2021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code ex
AFFECTS 1
BMC Helix
▸ DO Remote code execution — patch the affected products on priority.
#rce
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.3
NVD
2026-07-02
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.1
NVD
2026-07-08
IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
#unpatched#sql-injection#password-reset
Critical
CVSS 9.1
NVD
2026-06-29
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.
When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 2
Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 2
Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 2
Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate
▸ DO Critical severity — schedule patching of the affected products.