Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Critical
NVD
2026-05-29
AFFECTS 1
Security Service Edge (Formerly McAfee MVISION)
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-28
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-22
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-22
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-22
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-22
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-20
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-13
AFFECTS 1
Mendix Cloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-13
AFFECTS 1
Mendix Cloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-04-14
AFFECTS 12
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+6 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-04-03
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-04-03
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-04-03
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-04-03
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-01-23
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2024-01-04
AFFECTS 1
GitHub Enterprise Cloud
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2023-09-12
AFFECTS 1
Fortify on Demand
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2023-03-17
AFFECTS 1
Cloud Insights
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2023-02-14
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2022-08-05
AFFECTS 1
Cloud Insights
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2021-12-10
AFFECTS 10
Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Cloud Insights
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2021-09-16
AFFECTS 17
Aconex for DefenseClarityCloud InsightsFederal Managed Cloud ServicesFusion CloudGeneral Support Systems (GSS)
+11 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2021-04-09
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2020-05-21
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2020-05-06
AFFECTS 8
Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal
+2 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2019-08-08
AFFECTS 7
Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)WebEx Contact Center Enterprise for Government (WxCCE-G)
+1 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2019-08-07
AFFECTS 7
Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)WebEx Contact Center Enterprise for Government (WxCCE-G)
+1 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2018-01-29
AFFECTS 8
Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal
+2 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2017-05-23
AFFECTS 11
Aconex for DefenseCloud InsightsFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government Cloud
+5 more
▸ DO Critical severity — schedule patching of the affected products.
High
CVSS 8.7
NVD
2026-07-03
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Patch the affected products and confirm your instances are covered.
High
CVSS 8.5
NVD
2026-06-30
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Patch the affected products and confirm your instances are covered.
High
CVSS 8.1
NVD
2026-07-08
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Patch the affected products and confirm your instances are covered.
High
CVSS 8.1
NVD
2026-07-07
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators sh
AFFECTS 7
ArcGIS Online (AGO)ArcGIS Online (AGO) ModerateAzure Commercial CloudAzure Government (includes Dynamics 365)Esri Managed Cloud Services Advanced PlusMicrosoft Office 365 GCC High
+1 more
▸ DO Patch the affected products and confirm your instances are covered.
High
⚡ RCE
CVSS 8.1
NVD
2026-06-22
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker i
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Remote code execution — patch the affected products on priority.
#rce
High
CVSS 7.6
NVD
2026-06-30
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Patch the affected products and confirm your instances are covered.
High
⚡ RCE
CVSS 7.5
NVD
2026-06-30
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators);
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Remote code execution — patch the affected products on priority.
#rce
High
CVSS 7.4
NVD
2026-06-30
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Patch the affected products and confirm your instances are covered.
High
CVSS 7.1
NVD
2026-06-30
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Patch the affected products and confirm your instances are covered.
Listed
CVSS 6.8
NVD
2026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol pat
AFFECTS 4
ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)
▸ DO Patch the affected products and confirm your instances are covered.
Listed
CVSS 6.5
NVD
2026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extensio
AFFECTS 8
Azure Commercial CloudAzure Government (includes Dynamics 365)ClarityGeneral Support Systems (GSS)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
+2 more
▸ DO Patch the affected products and confirm your instances are covered.