Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
KEV
2025-02-21
Microsoft Power Pages has an improper access control vulnerability actively exploited in the wild, allowing privilege escalation and bypassing user registration controls.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
KEV
2025-02-20
A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2025-02-18
A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#auth-bypass#rce
Exploited
⌖ KEV
KEV
2025-02-11
A Microsoft Windows vulnerability allows privilege escalation and potential data deletion, currently being exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
KEV
2025-02-11
A Microsoft Windows driver vulnerability allows local privilege escalation to SYSTEM, actively exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild
Exploited
⌖ KEV
⚡ RCE
KEV
2025-02-06
Microsoft Outlook's improper input validation allows attackers to bypass Protected View and execute code remotely, currently being exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2025-02-04
A Microsoft .NET Framework vulnerability allows attackers to expose sensitive information and potentially execute code remotely, currently being exploited in the wild.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild
Exploited
⌖ KEV
KEV
2025-01-14
Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2025-01-14
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow allowing local attackers to gain SYSTEM privileges.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2025-01-14
Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2025-01-13
BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.
AFFECTS 1
Secure Remote Access
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#supply-chain#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2025-01-07
Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#ransomware#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2024-12-30
Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2024-12-19
BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.
AFFECTS 1
Secure Remote Access
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#supply-chain
Exploited
⌖ KEV
KEV
2024-12-16
Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#data-breach#supply-chain
Exploited
⌖ KEV
KEV
2024-12-16
Microsoft Windows kernel-mode driver vulnerability CVE-2024-35250 allows local privilege escalation.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2024-12-10
Microsoft Windows CLFS driver heap-based buffer overflow allows local privilege escalation.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2024-11-21
Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#data-breach#auth-bypass
Exploited
⌖ KEV
⚡ RCE
KEV
2024-11-20
VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-11-20
VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.
AFFECTS 2
VMware Government Services (VGS)Workspace ONE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#privilege-escalation#ransomware#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-11-14
Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
⚡ RCE
KEV
2024-11-14
Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#sql-injection#unpatched#data-breach#supply-chain#negligence
Exploited
⌖ KEV
KEV
2024-11-12
Cisco ASA WebVPN XSS vulnerability allows remote script injection via unspecified parameter.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2024-11-12
Microsoft Windows NTLMv2 hash disclosure via file open enables user impersonation and credential theft.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#data-breach
Exploited
⌖ KEV
KEV
2024-11-07
Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.
AFFECTS 2
GCS-HIGHPalo Alto Networks Government Cloud Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#default-creds#unpatched
Exploited
⌖ KEV
KEV
2024-10-24
Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.
AFFECTS 9
AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
+3 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2024-10-09
Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#sql-injection#admin-privilege#ransomware-linked
Exploited
⌖ KEV
⚡ RCE
KEV
2024-10-09
Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#supply-chain
Exploited
⌖ KEV
⚡ RCE
KEV
2024-10-08
Microsoft Windows Management Console allows remote code execution via an unspecified vulnerability, enabling attackers to compromise systems without user interaction.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2024-10-08
Microsoft Windows MSHTML platform contains a spoofing vulnerability actively exploited in the KEV list that causes confidentiality loss.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-10-02
Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-30
SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.
AFFECTS 2
SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
KEV
2024-09-24
Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#auth-bypass#supply-chain
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-19
Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-18
Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-18
Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.
AFFECTS 10
Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM)
+4 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#ransomware#supply-chain#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-18
Microsoft SQL Server Reporting Services exploited a deserialization RCE vulnerability (CVE-2020-0618) allowing authenticated attackers to execute code as the service account.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-17
Adobe Flash Player's unpatched double-free RCE vulnerability (CVE-2014-0502) remains exploitable due to the product's EOL status.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-17
Adobe Flash Player's integer underflow vulnerability enabled remote code execution and is actively exploited, posing a critical risk to legacy systems still in use.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2024-09-17
Adobe Flash Player's unpatched EOL status leaves remote code execution vulnerabilities perpetually exploitable.
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched#ransomware