Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
275 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2022-03-03

CVE-2012-1723

A critical, actively exploited Java vulnerability allows remote code execution, impacting systems using outdated Java SE Runtime Environments (JRE).

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-02-15

CVE-2019-0752

Microsoft Internet Explorer's type confusion vulnerability allowed remote code execution and was actively exploited, highlighting the risks of using unsupported software in DIB environments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-02-15

CVE-2018-15982

Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-02-15

CVE-2018-8174

A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-02-10

CVE-2017-0145

Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-02-10

CVE-2017-10271

Oracle WebLogic Server had a remotely exploitable code execution vulnerability actively linked to ransomware attacks.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-02-10

CVE-2020-0796

A critical SMBv3 vulnerability allowed remote code execution, actively exploited and linked to ransomware attacks, impacting DIB organizations reliant on Microsoft infrastructure.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-02-10

CVE-2017-0144

Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-01-28

CVE-2020-0787

A Microsoft Windows vulnerability allowed privilege escalation to system-level access via improper symbolic link handling, actively exploited in ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2022-01-21

CVE-2018-8453

A Microsoft Win32k vulnerability allowed privilege escalation and was actively exploited, likely in ransomware attacks, impacting Windows systems widely used in the DIB.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild
Exploited ⌖ KEV KEV 2022-01-18

CVE-2021-21975

VMware's vRealize Operations Manager API had a critical SSRF vulnerability exploited in the wild, potentially leading to credential theft and system compromise.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2022-01-10

CVE-2019-1579

A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2022-01-10

CVE-2019-1458

A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2022-01-10

CVE-2019-2725

Oracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2021-12-15

CVE-2021-43890

A Microsoft Windows vulnerability allowed attackers to spoof installations, potentially delivering malware and compromising system integrity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-12-10

CVE-2017-12149

A vulnerability in Red Hat JBoss Application Server allowed attackers to execute arbitrary code remotely, linked to ransomware activity.

AFFECTS 1 Red Hat OpenShift Service on AWS (ROSA)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-17

CVE-2021-42321

Microsoft Exchange Server vulnerabilities allowed authenticated attackers to execute remote code, impacting DIB organizations using the platform.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-17

CVE-2021-40449

A Microsoft Windows vulnerability allowed authenticated users to escalate privileges, actively exploited and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-26411

A memory corruption vulnerability in unsupported Microsoft Internet Explorer allowed exploitation and was actively exploited in the wild, linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2021-11-03

CVE-2014-1812

An authenticated attacker can decrypt and escalate privileges within a Windows Active Directory domain via a Group Policy Preferences vulnerability.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2016-0167

A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-0143

A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-0199

A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-11882

A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2021-11-03

CVE-2018-2380

A path traversal vulnerability in SAP CRM allowed attackers to access sensitive files without authorization, and it's currently being exploited in the wild.

AFFECTS 2 SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2018-4878

Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-0604

Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-0708

BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2021-11-03

CVE-2019-11510

Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-11539

Authenticated admins of Ivanti Pulse Connect Secure/Policy Secure could inject and execute commands via the web interface, actively exploited in ransomware attacks.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-11634

Citrix Workspace software had a remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary code on affected systems.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-1215

A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2021-11-03

CVE-2019-13608

Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-1367

A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2021-11-03

CVE-2019-19781

Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-5544

VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-0688

Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-0878

Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-1472

Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce#negligence
Exploited ⌖ KEV KEV 2021-11-03

CVE-2020-3580

Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
◀ PREV PAGE 04 / 07 NEXT ▶