Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
1035 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-21985

VMware vCenter Server RCE due to unpatched input validation flaw

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-5544

VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2021-11-03

CVE-2021-34527

PrintNightmare allowed attackers to execute code with SYSTEM privileges on Windows systems via the Print Spooler service, actively exploited in ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2021-11-03

CVE-2019-19781

Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-0143

A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV KEV 2021-11-03

CVE-2021-22005

VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild
Exploited ⌖ KEV KEV 2021-11-03

CVE-2020-3580

Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-21972

VMware vCenter Server RCE due to unpatched plugin exploited in wild

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2016-0167

A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-0708

BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-0688

Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-3992

VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-27102

Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited ⌖ KEV KEV 2021-11-03

CVE-2021-27103

Accellion FTA's SSRF vulnerability was actively exploited, linked to ransomware attacks, impacting DIB organizations using the platform for data transfer and storage.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-22893

Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-26858

Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-27065

Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-1367

A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-0604

Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-0878

Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2021-11-03

CVE-2019-11510

Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ◐ 0-DAY KEV 2021-11-03

CVE-2021-27101

Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-27104

Accellion FTA's OS command injection vulnerability allowed attackers to execute arbitrary commands, leading to data exfiltration and ransomware attacks.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-11882

A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-1732

A Microsoft Win32k vulnerability allows privilege escalation and is actively exploited in ransomware attacks, impacting DIB organizations using Windows systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-21

CVE-2026-69836

A deserialization of untrusted data vulnerability in Microsoft Entra ID allowed remote code execution over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-18

CVE-2026-59310

Unauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors.

AFFECTS 4 ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-18

CVE-2026-33824

A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-18

CVE-2026-55040

Microsoft SharePoint's weak authentication flaw lets attackers bypass security controls over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-11

CVE-2026-68820

A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock allows local privilege escalation and is actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-11

CVE-2026-20349

Cisco ASA/FTD devices have an unpatched heap inspection vulnerability allowing remote denial of service.

AFFECTS 8 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-04

CVE-2026-9198

IBM Langflow Code Injection Vulnerability allows RCE.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-07-29

CVE-2026-20316

Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#default-creds#hardcoded-creds#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-22

CVE-2026-50522

Microsoft SharePoint RCE due to untrusted data deserialization

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-16

CVE-2026-58644

Microsoft SharePoint RCE due to untrusted data deserialization

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-15

CVE-2026-46817

Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-14

CVE-2026-56164

Unpatched RCE in SharePoint Server

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-14

CVE-2026-56155

Authorized attackers can elevate privileges in Microsoft AD FS due to insufficient access control granularity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-13

CVE-2008-4128

Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-07

CVE-2026-48282

Adobe ColdFusion allows arbitrary code execution via path traversal, enabling attackers to run commands as the current user.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild
◀ PREV PAGE 05 / 26 NEXT ▶