Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2021-11-03
Accellion FTA's SSRF vulnerability was actively exploited, linked to ransomware attacks, impacting DIB organizations using the platform for data transfer and storage.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to bypass security features and potentially deploy ransomware, impacting DIB organizations reliant on email infrastructure.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#rce#negligence
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
VMware vCenter Server RCE due to unpatched input validation flaw
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A memory corruption vulnerability in unsupported Microsoft Internet Explorer allowed exploitation and was actively exploited in the wild, linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
◐ 0-DAY
KEV
2021-11-03
Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.
AFFECTS 1
Kiteworks Federal Cloud
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
◐ 0-DAY
KEV
2021-11-03
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often linked to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
CVE-2021-26857: Microsoft Exchange Server RCE exploited in wild
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#ransomware#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-08-26
A privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool allowed local users to escalate privileges via a symlink attack on a predictable file.
AFFECTS 1
Red Hat OpenShift Service on AWS (ROSA)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#privilege-escalation#unpatched
Exploited
⌖ KEV
KEV
2026-08-26
A race condition in Red Hat's libuser allowed authenticated local users to corrupt /etc/passwd, causing denial of service or privilege escalation.
AFFECTS 1
Red Hat OpenShift Service on AWS (ROSA)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2026-08-26
An unpatched remote code execution flaw in Microsoft SQL Server allowed attackers to execute arbitrary code as the database engine service account.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-08-26
An unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452.
AFFECTS 1
Citrix for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#rce#unpatched
Exploited
⌖ KEV
KEV
2026-08-24
Oracle HTTP Server and Weblogic Server Proxy Plug-in suffer from an improper access control flaw allowing unauthorized data manipulation and full data access.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2026-08-21
A deserialization of untrusted data vulnerability in Microsoft Entra ID allowed remote code execution over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-08-18
A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-08-18
Unauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors.
AFFECTS 4
ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-08-18
Microsoft SharePoint's weak authentication flaw lets attackers bypass security controls over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-08-11
A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock allows local privilege escalation and is actively exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-08-11
Cisco ASA/FTD devices have an unpatched heap inspection vulnerability allowing remote denial of service.
AFFECTS 8
Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-08-04
IBM Langflow Code Injection Vulnerability allows RCE.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2026-07-29
Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#default-creds#hardcoded-creds#supply-chain
Exploited
⌖ KEV
⚡ RCE
KEV
2026-07-22
Microsoft SharePoint RCE due to untrusted data deserialization
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-07-16
Microsoft SharePoint RCE due to untrusted data deserialization
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2026-07-15
Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2026-07-14
Authorized attackers can elevate privileges in Microsoft AD FS due to insufficient access control granularity.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched