Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
861 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1062
Correlated CVEs
861
Under active attack
286
Critical
767
High
605
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2018-4878

Adobe Flash Player's use-after-free vulnerability allows for code execution and is actively exploited, despite the product's end-of-life status and lack of updates.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-27102

Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2016-0167

A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2021-11-03

CVE-2021-27103

Accellion FTA's SSRF vulnerability was actively exploited, linked to ransomware attacks, impacting DIB organizations using the platform for data transfer and storage.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-31207

Microsoft Exchange Server vulnerabilities allowed attackers to bypass security features and potentially deploy ransomware, impacting DIB organizations reliant on email infrastructure.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#data-breach#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-0708

BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-0199

A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-1472

Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce#negligence
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-3992

VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-0604

Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-5544

VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-26858

Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-27065

Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2021-11-03

CVE-2019-13608

Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2019-1367

A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-21985

VMware vCenter Server RCE due to unpatched input validation flaw

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-26411

A memory corruption vulnerability in unsupported Microsoft Internet Explorer allowed exploitation and was actively exploited in the wild, linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2021-11-03

CVE-2021-26855

Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ◐ 0-DAY KEV 2021-11-03

CVE-2021-27101

Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.

AFFECTS 1 Kiteworks Federal Cloud

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2021-11-03

CVE-2021-34473

Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often linked to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2017-11882

A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2020-0688

Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2021-11-03

CVE-2021-26857

CVE-2021-26857: Microsoft Exchange Server RCE exploited in wild

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-26

CVE-2015-5287

A privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool allowed local users to escalate privileges via a symlink attack on a predictable file.

AFFECTS 1 Red Hat OpenShift Service on AWS (ROSA)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#unpatched
Exploited ⌖ KEV KEV 2026-08-26

CVE-2015-3246

A race condition in Red Hat's libuser allowed authenticated local users to corrupt /etc/passwd, causing denial of service or privilege escalation.

AFFECTS 1 Red Hat OpenShift Service on AWS (ROSA)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-26

CVE-2019-1068

An unpatched remote code execution flaw in Microsoft SQL Server allowed attackers to execute arbitrary code as the database engine service account.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-26

CVE-2026-8452

An unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#rce#unpatched
Exploited ⌖ KEV KEV 2026-08-24

CVE-2026-21962

Oracle HTTP Server and Weblogic Server Proxy Plug-in suffer from an improper access control flaw allowing unauthorized data manipulation and full data access.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-21

CVE-2026-69836

A deserialization of untrusted data vulnerability in Microsoft Entra ID allowed remote code execution over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-18

CVE-2026-33824

A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-18

CVE-2026-59310

Unauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors.

AFFECTS 4 ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-18

CVE-2026-55040

Microsoft SharePoint's weak authentication flaw lets attackers bypass security controls over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-11

CVE-2026-68820

A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock allows local privilege escalation and is actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-08-11

CVE-2026-20349

Cisco ASA/FTD devices have an unpatched heap inspection vulnerability allowing remote denial of service.

AFFECTS 8 Cisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)Duo Federal +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-08-04

CVE-2026-9198

IBM Langflow Code Injection Vulnerability allows RCE.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-07-29

CVE-2026-20316

Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#default-creds#hardcoded-creds#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-22

CVE-2026-50522

Microsoft SharePoint RCE due to untrusted data deserialization

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-16

CVE-2026-58644

Microsoft SharePoint RCE due to untrusted data deserialization

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-15

CVE-2026-46817

Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-14

CVE-2026-56155

Authorized attackers can elevate privileges in Microsoft AD FS due to insufficient access control granularity.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
◀ PREV PAGE 05 / 22 NEXT ▶