Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
KEV
2022-03-03
A Microsoft Windows vulnerability allowed attackers to escalate privileges to administrator level, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-02-15
A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-02-15
Microsoft Internet Explorer's type confusion vulnerability allowed remote code execution and was actively exploited, highlighting the risks of using unsupported software in DIB environments.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-02-15
Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-02-10
A critical SMBv3 vulnerability allowed remote code execution, actively exploited and linked to ransomware attacks, impacting DIB organizations reliant on Microsoft infrastructure.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-02-10
Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-02-10
Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-02-10
Oracle WebLogic Server had a remotely exploitable code execution vulnerability actively linked to ransomware attacks.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-01-28
A Microsoft Windows vulnerability allowed privilege escalation to system-level access via improper symbolic link handling, actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2022-01-21
A Microsoft Win32k vulnerability allowed privilege escalation and was actively exploited, likely in ransomware attacks, impacting Windows systems widely used in the DIB.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
KEV
2022-01-18
VMware's vRealize Operations Manager API had a critical SSRF vulnerability exploited in the wild, potentially leading to credential theft and system compromise.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2022-01-10
A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2022-01-10
Oracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2022-01-10
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2021-12-15
A Microsoft Windows vulnerability allowed attackers to spoof installations, potentially delivering malware and compromising system integrity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-12-10
A vulnerability in Red Hat JBoss Application Server allowed attackers to execute arbitrary code remotely, linked to ransomware activity.
AFFECTS 1
Red Hat OpenShift Service on AWS (ROSA)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-17
A Microsoft Windows vulnerability allowed authenticated users to escalate privileges, actively exploited and linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-17
Microsoft Exchange Server vulnerabilities allowed authenticated attackers to execute remote code, impacting DIB organizations using the platform.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft OMI vulnerability allowed remote code execution, actively exploited in ransomware attacks, impacting Azure VM Management Extensions.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to bypass security features and potentially deploy ransomware, impacting DIB organizations reliant on email infrastructure.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Accellion FTA's OS command injection vulnerability allowed attackers to execute arbitrary commands, leading to data exfiltration and ransomware attacks.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce#negligence
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
Accellion FTA's SSRF vulnerability was actively exploited, linked to ransomware attacks, impacting DIB organizations using the platform for data transfer and storage.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
KEV
2021-11-03
An authenticated attacker can decrypt and escalate privileges within a Windows Active Directory domain via a Group Policy Preferences vulnerability.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
CVE-2021-26857: Microsoft Exchange Server RCE exploited in wild
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Exchange Server vulnerability allowed privilege escalation and was actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Citrix Workspace software had a remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary code on affected systems.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
◐ 0-DAY
KEV
2021-11-03
Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild