Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
203 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Critical NVD 2025-04-24

CVE-2025-31324

AFFECTS 2 SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2025-04-03

CVE-2025-22457

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2025-01-08

CVE-2025-0282

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2024-01-12

CVE-2024-21887

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2024-01-04

CVE-2024-22051

AFFECTS 1 GitHub Enterprise Cloud

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2023-09-12

CVE-2023-4501

AFFECTS 1 Fortify on Demand

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2023-08-29

CVE-2023-41265

AFFECTS 1 Qlik Cloud Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2023-07-25

CVE-2023-35078

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2023-07-19

CVE-2023-3519

AFFECTS 1 Citrix for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2023-03-17

CVE-2023-28531

AFFECTS 1 Cloud Insights

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2023-02-14

CVE-2023-21716

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2022-08-05

CVE-2022-37434

AFFECTS 1 Cloud Insights

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-12-10

CVE-2021-44228

AFFECTS 10 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Cloud Insights +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-12-08

CVE-2021-44529

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-09-16

CVE-2021-40438

AFFECTS 17 Aconex for DefenseClarityCloud InsightsFederal Managed Cloud ServicesFusion CloudGeneral Support Systems (GSS) +11 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-05-26

CVE-2021-21985

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-04-23

CVE-2021-22893

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-04-09

CVE-2021-20021

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2021-02-24

CVE-2021-21972

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2020-10-20

CVE-2020-3992

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2020-05-21

CVE-2020-0901

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2020-05-06

CVE-2020-3187

AFFECTS 8 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal +2 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2020-03-12

CVE-2020-0796

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2019-12-27

CVE-2019-19781

AFFECTS 1 Citrix for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2019-05-22

CVE-2019-11634

AFFECTS 1 Citrix for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2019-04-26

CVE-2019-2725

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2018-01-29

CVE-2018-0101

AFFECTS 8 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal +2 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2017-05-23

CVE-2016-9841

AFFECTS 11 Aconex for DefenseCloud InsightsFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government Cloud +5 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2016-04-07

CVE-2016-1019

AFFECTS 14 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +8 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2012-08-28

CVE-2012-4681

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2012-05-03

CVE-2012-1710

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2010-08-11

CVE-2010-2861

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Critical severity — schedule patching of the affected products.

High CVSS 8.7 NVD 2026-07-03

CVE-2026-57983

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High CVSS 8.5 NVD 2026-06-30

CVE-2026-11714

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High CVSS 8.1 NVD 2026-07-08

CVE-2026-3144

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High CVSS 8.1 NVD 2026-07-07

CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators sh

AFFECTS 7 ArcGIS Online (AGO)ArcGIS Online (AGO) ModerateAzure Commercial CloudAzure Government (includes Dynamics 365)Esri Managed Cloud Services Advanced PlusMicrosoft Office 365 GCC High +1 more

▸ DO  Patch the affected products and confirm your instances are covered.

High ⚡ RCE CVSS 8.1 NVD 2026-06-22

CVE-2026-9072

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker i

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Remote code execution — patch the affected products on priority.

#rce
High CVSS 7.6 NVD 2026-06-30

CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High ⚡ RCE CVSS 7.5 NVD 2026-06-30

CVE-2026-13772

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators);

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Remote code execution — patch the affected products on priority.

#rce
High CVSS 7.4 NVD 2026-06-30

CVE-2026-11541

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

◀ PREV PAGE 03 / 06 NEXT ▶