Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
275 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

1035
Correlated CVEs
856
Under active attack
275
Critical
750
High
595
RCE
Critical CVSS 9.1 NVD 2026-07-08

CVE-2026-9074

IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

#unpatched#sql-injection#password-reset
Critical CVSS 9.1 NVD 2026-06-29

CVE-2026-11720

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-19

CVE-2026-16919

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-19

CVE-2026-76312

AFFECTS 2 Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-19

CVE-2026-76311

AFFECTS 2 Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-19

CVE-2026-76310

AFFECTS 2 Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-60977

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-70905

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-61258

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-61248

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-61241

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-61066

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-61003

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-61001

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-18

CVE-2026-60990

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-12

CVE-2026-17276

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-12

CVE-2026-16860

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-08-05

CVE-2026-17556

AFFECTS 1 GitHub Enterprise Cloud

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-07-31

CVE-2026-14537

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-07-29

CVE-2026-14529

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-07-14

CVE-2026-54118

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-07-14

CVE-2026-54117

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-18

CVE-2026-12569

AFFECTS 1 PTC Cloud Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-18

CVE-2026-11718

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-18

CVE-2026-11717

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-09

CVE-2026-34691

AFFECTS 14 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +8 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-09

CVE-2026-10523

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-09

CVE-2026-47928

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11120

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-48567

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10966

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10971

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10972

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10974

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10990

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11002

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11029

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11113

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10931

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-05-29

CVE-2025-41276

AFFECTS 1 Security Service Edge (Formerly McAfee MVISION)

▸ DO  Critical severity — schedule patching of the affected products.

◀ PREV PAGE 06 / 07 NEXT ▶