Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
KEV
2022-04-13
A Microsoft Windows driver vulnerability allows privilege escalation and is actively exploited in ransomware attacks, impacting CMMC compliance for DIB organizations using vulnerable systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-04-11
A Microsoft Active Directory vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-04-11
A Microsoft Active Directory vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-04-06
Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
KEV
2022-03-28
A Microsoft Windows flaw allowed local privilege escalation via crafted applications, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-28
A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-03-28
A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-28
A Microsoft Windows vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-28
A Microsoft Windows flaw allowed attackers to escalate privileges by running crafted applications, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-28
A Microsoft Office vulnerability allowed authenticated users to inject SQL and potentially execute arbitrary code remotely, actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-28
A Microsoft Internet Explorer use-after-free vulnerability allowed remote code execution via crafted websites and is actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-28
Oracle Java SE vulnerabilities are actively exploited and linked to ransomware attacks, demonstrating a persistent risk for DIB organizations using outdated Java installations.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-25
Citrix ShareFile allowed unauthenticated attackers to remotely compromise storage zones controllers, actively exploited and linked to ransomware activity.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-03-25
A flaw in Palo Alto Networks' PAN-OS allowed attackers to bypass authentication, potentially granting unauthorized access to networks and systems.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-25
A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
KEV
2022-03-25
Adobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-25
VMware Tanzu Spring Data Commons contained a remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using this software stack.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-25
A Microsoft Windows Print Spooler vulnerability allowed privilege escalation and was actively exploited, likely contributing to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows flaw allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on Windows infrastructure.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows UPnP service vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-03-15
A Microsoft Win32k vulnerability allowed local privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows OS and Server deployments.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows vulnerability allowed privilege escalation on AppX Deployment Servers, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems for software deployment and management.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows flaw allowed attackers to gain elevated privileges by manipulating hard links, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
Microsoft's Task Scheduler had a privilege escalation vulnerability actively exploited by ransomware actors, allowing attackers to gain elevated system access.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2022-03-15
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows kernel vulnerability allowed attackers to escalate privileges and execute arbitrary code, actively exploited in ransomware campaigns and impacting DIB organizations using Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-15
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2022-03-07
A decade-old Adobe BlazeDS vulnerability is actively exploited, potentially exposing sensitive information in systems using LifeCycle and ColdFusion applications.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
A critical, actively exploited Java vulnerability allows remote code execution, impacting systems using outdated Java SE Runtime Environments (JRE).
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
A Microsoft Windows vulnerability allowed attackers to escalate privileges to administrator level, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-03-03
Microsoft Exchange Server vulnerabilities allowed attackers to impersonate users, linked to ransomware activity and actively exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
A Windows Installer vulnerability allowed privilege escalation and was actively exploited in ransomware attacks, impacting DIB organizations reliant on Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
A critical Adobe Reader/Acrobat vulnerability (CVE-2010-0188) allowed arbitrary code execution and is actively exploited, often linked to ransomware attacks.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
Oracle Java SE's Concurrency component had a remotely exploitable arbitrary code execution vulnerability, actively targeted by ransomware actors, highlighting the risk of outdated software in DIB environments.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
Adobe Flash Player vulnerabilities allowed attackers to execute arbitrary code via malicious SWF files, and no patches are available due to the product's end-of-life status.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
Adobe Flash Player, now defunct, contained a critical, actively exploited remote code execution vulnerability, leaving systems perpetually exposed to attack.
AFFECTS 14
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+8 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild