Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Critical
CVSS 9.1
NVD
2026-07-08
IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
#unpatched#sql-injection#password-reset
Critical
CVSS 9.1
NVD
2026-06-29
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.
When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 2
Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 2
Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-19
AFFECTS 2
Splunk Cloud Platform for FedRAMP HighSplunk Cloud Platform for FedRAMP Moderate
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-18
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-12
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-12
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-08-05
AFFECTS 1
GitHub Enterprise Cloud
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-07-31
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-07-29
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-07-14
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-07-14
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-18
AFFECTS 1
PTC Cloud Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-18
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-18
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-09
AFFECTS 14
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+8 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-09
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-09
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-29
AFFECTS 1
Security Service Edge (Formerly McAfee MVISION)
▸ DO Critical severity — schedule patching of the affected products.