Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
203 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
High CVSS 7.1 NVD 2026-06-30

CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

Listed CVSS 6.8 NVD 2026-07-10

CVE-2026-57216

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol pat

AFFECTS 4 ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)

▸ DO  Patch the affected products and confirm your instances are covered.

Listed CVSS 6.5 NVD 2026-07-10

CVE-2026-57211

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extensio

AFFECTS 8 Azure Commercial CloudAzure Government (includes Dynamics 365)ClarityGeneral Support Systems (GSS)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services +2 more

▸ DO  Patch the affected products and confirm your instances are covered.

Listed ⚡ RCE CVSS 6.0 NVD 2026-06-30

CVE-2026-13773

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Remote code execution — patch the affected products on priority.

#rce
Listed ⚡ RCE CVSS 5.3 NVD 2026-07-06

CVE-2026-9182

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.

AFFECTS 7 ArcGIS Online (AGO)ArcGIS Online (AGO) ModerateAzure Commercial CloudAzure Government (includes Dynamics 365)Esri Managed Cloud Services Advanced PlusMicrosoft Office 365 GCC High +1 more

▸ DO  Remote code execution — patch the affected products on priority.

#rce
Listed CVSS 4.8 NVD 2026-07-02

CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-16961

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-16867

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-16815

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-18249

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-17206

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-17197

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-18193

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-17481

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-13

CVE-2026-17101

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-12

CVE-2026-10543

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

Listed NVD 2026-08-12

CVE-2026-17616

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-12

CVE-2026-18847

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-12

CVE-2026-13433

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-12

CVE-2026-17111

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-12

CVE-2026-10534

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-11

CVE-2026-57104

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-11

CVE-2026-65768

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-07

CVE-2026-62836

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-05

CVE-2026-17617

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-05

CVE-2026-10025

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-05

CVE-2026-8400

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-08-04

CVE-2026-66321

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-30

CVE-2026-14522

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-28

CVE-2026-14974

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-28

CVE-2026-14976

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-28

CVE-2026-16184

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-20

CVE-2026-12341

AFFECTS 2 Identity SecurityIdentity Security - SaaS

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-17

CVE-2026-13473

AFFECTS 9 Azure Commercial CloudAzure Government (includes Dynamics 365)IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility Management +3 more

▸ DO  Patch the affected products and confirm your instances are covered.

Listed NVD 2026-07-17

CVE-2026-14501

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-17

CVE-2026-13448

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-15

CVE-2026-20157

AFFECTS 8 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal +2 more

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-15

CVE-2026-20156

AFFECTS 8 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal +2 more

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-14

CVE-2026-49181

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

High NVD 2026-07-14

CVE-2026-50330

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Patch the affected products and confirm your instances are covered.

◀ PREV PAGE 04 / 06 NEXT ▶