Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
1035 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2026-07-01

CVE-2026-45659

Microsoft SharePoint Server allows remote code execution via deserialization of untrusted data.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#data-breach#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-06-25

CVE-2026-20230

Cisco Unified CM SSRF vulnerability allows unauthenticated remote attackers to write files to the OS and escalate to root.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#rce#privilege-escalation
Exploited ⌖ KEV KEV 2026-06-18

CVE-2026-20253

Splunk Enterprise allows unauthenticated users to create or truncate arbitrary files via a PostgreSQL sidecar service endpoint.

AFFECTS 2 Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV KEV 2026-06-15

CVE-2026-20262

Cisco Catalyst SD-WAN Manager allows authenticated attackers to overwrite arbitrary files via path traversal.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-06-11

CVE-2026-10520

Ivanti Sentry allows remote unauthenticated root access via command injection when appliances are unmanaged and externally reachable.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-06-09

CVE-2026-11645

Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-06-09

CVE-2026-20245

Cisco SD-WAN Manager allows authenticated local attackers to execute arbitrary root commands via crafted file uploads.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-06-01

CVE-2024-21182

Oracle WebLogic Server vulnerability CVE-2024-21182 allows unauthenticated remote access to critical data via T3/IIOP protocols.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV KEV 2026-05-29

CVE-2026-0257

Palo Alto Networks PAN-OS allows attackers to bypass authentication and establish unauthorized VPN connections.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#auth-bypass
Exploited ⌖ KEV KEV 2026-05-21

CVE-2026-34926

Trend Micro Apex One on-premise software allows local attackers to inject malicious code into agents via a directory traversal flaw.

AFFECTS 2 Trend Micro Cloud One for GovernmentTrend Micro Vision One for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-20

CVE-2010-0806

Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-20

CVE-2010-0249

Microsoft Internet Explorer use-after-free vulnerability (CVE-2010-0249) allows remote code execution on EoL browsers.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV KEV 2026-05-20

CVE-2026-45498

Microsoft Defender allows denial of service via unspecified vulnerability, impacting DIB systems reliant on endpoint protection.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-20

CVE-2008-4250

Microsoft Windows Server Service buffer overflow vulnerability (CVE-2008-4250) enabled remote code execution via crafted RPC requests.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-20

CVE-2009-3459

Adobe Acrobat and Reader exploited a heap-based buffer overflow vulnerability allowing remote code execution via crafted PDF files.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-20

CVE-2009-1537

Microsoft DirectX contained a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter allowing remote code execution via crafted media files.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV KEV 2026-05-20

CVE-2026-41091

Microsoft Defender allows local privilege escalation via link following, enabling unauthorized access to sensitive systems.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation
Exploited ⌖ KEV KEV 2026-05-15

CVE-2026-42897

Microsoft Exchange Server XSS vulnerability allows arbitrary JavaScript execution in Outlook Web Access browser context.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-14

CVE-2026-20182

Cisco Catalyst SD-WAN Controller allows unauthenticated remote attackers to bypass authentication and gain administrative privileges.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#auth-bypass#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-07

CVE-2026-6973

Ivanti EPMM allows remote code execution for authenticated admins via improper input validation.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-05-06

CVE-2026-0300

Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#data-breach#default-creds
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-28

CVE-2026-32202

Microsoft Windows Shell allows network spoofing via a protection mechanism failure, enabling attackers to bypass authentication and execute commands.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2026-04-20

CVE-2026-20128

Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing local attackers to escalate privileges by reading credential files.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#default-creds#hardcoded-creds#unpatched#privilege-escalation
Exploited ⌖ KEV KEV 2026-04-20

CVE-2026-20133

Cisco Catalyst SD-WAN Manager allows remote attackers to view sensitive information due to an exposure vulnerability actively exploited in the wild.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#data-breach#unpatched
Exploited ⌖ KEV KEV 2026-04-20

CVE-2026-20122

Cisco Catalyst SD-WAN Manager allows attackers to overwrite arbitrary files and gain vmanage privileges via local file upload.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-14

CVE-2009-0238

Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#data-breach#unpatched
Exploited ⌖ KEV KEV 2026-04-14

CVE-2026-32201

Microsoft SharePoint Server is actively exploited via CVE-2026-32201, enabling network spoofing that threatens DIB data integrity and trust.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#supply-chain#data-breach
Exploited ⌖ KEV KEV 2026-04-13

CVE-2025-60710

Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#privilege-escalation#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-13

CVE-2012-1854

Microsoft VBA allows remote code execution via insecure library loading, actively exploited and linked to ransomware.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-13

CVE-2026-34621

Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2026-04-13

CVE-2020-9715

Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched#ransomware
Exploited ⌖ KEV KEV 2026-04-13

CVE-2023-36424

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability enabling privilege escalation.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-08

CVE-2026-1340

Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-01

CVE-2026-5281

Google Dawn (Chrome/Edge/Opera) use-after-free vulnerability enables remote code execution via crafted HTML.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain
Exploited ⌖ KEV KEV 2026-03-30

CVE-2026-3055

Citrix NetScaler SAML IDP configuration allows out-of-bounds memory reads, enabling attackers to read sensitive data without code execution.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV ⚡ RCE KEV 2026-03-18

CVE-2026-20963

Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-03-13

CVE-2026-3910

Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#ransomware#supply-chain#data-breach#unpatched
Exploited ⌖ KEV KEV 2026-03-13

CVE-2026-3909

Google Skia contains an actively exploited out-of-bounds write vulnerability enabling remote memory access via crafted HTML.

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#ransomware#unpatched
Exploited ⌖ KEV KEV 2026-03-09

CVE-2026-1603

Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#exploited-in-wild#auth-bypass#data-breach#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-03-03

CVE-2026-22719

Broadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations.

AFFECTS 4 ClarityGeneral Support Systems (GSS)RallySymantec Gov Cloud Security (GCS)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#rce#exploited-in-wild#unpatched
◀ PREV PAGE 06 / 26 NEXT ▶