Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Win32k vulnerability allows privilege escalation and is actively exploited in ransomware attacks, impacting DIB organizations using Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
VMware vCenter Server RCE due to unpatched plugin exploited in wild
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
VMware vCenter Server RCE due to unpatched input validation flaw
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
KEV
2021-11-03
VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
CVE-2021-26857: Microsoft Exchange Server RCE exploited in wild
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
◐ 0-DAY
KEV
2021-11-03
Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
Accellion FTA's SSRF vulnerability was actively exploited, linked to ransomware attacks, impacting DIB organizations using the platform for data transfer and storage.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Accellion FTA's OS command injection vulnerability allowed attackers to execute arbitrary commands, leading to data exfiltration and ransomware attacks.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to bypass security features and potentially deploy ransomware, impacting DIB organizations reliant on email infrastructure.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Exchange Server vulnerability allowed privilege escalation and was actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
PrintNightmare allowed attackers to execute code with SYSTEM privileges on Windows systems via the Print Spooler service, actively exploited in ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Windows CLFS driver vulnerability allows privilege escalation, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft OMI vulnerability allowed remote code execution, actively exploited in ransomware attacks, impacting Azure VM Management Extensions.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft MSHTML vulnerability allowed for remote code execution and was actively exploited, potentially linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Critical
CVSS 10.0
NVD
2026-06-30
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.9
NVD
2026-07-06
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited pr
AFFECTS 1
Secure Remote Access
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-07-06
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, i
AFFECTS 1
Secure Remote Access
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
⚡ RCE
◐ 0-DAY
CVSS 9.8
NVD
2026-06-30
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Remote code execution — patch the affected products on priority.
#rce#zero-day
Critical
CVSS 9.8
NVD
2026-06-30
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured
AFFECTS 1
Citrix for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AFFECTS 1
Citrix for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
⚡ RCE
CVSS 9.8
NVD
2021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code ex
AFFECTS 1
BMC Helix
▸ DO Remote code execution — patch the affected products on priority.
#rce
Critical
CVSS 9.6
NVD
2026-06-30
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.3
NVD
2026-07-02
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.