CVE-2025-22224
VMware ESXi and Workstation vulnerabilities allow code execution with local admin privileges, and are currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
VMware ESXi and Workstation vulnerabilities allow code execution with local admin privileges, and are currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's Partner Center had a privilege escalation vulnerability actively exploited in the wild, allowing attackers to gain elevated access to systems and data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Agile PLM has a deserialization vulnerability actively exploited by attackers to compromise systems via HTTP network access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Power Pages has an improper access control vulnerability actively exploited in the wild, allowing privilege escalation and bypassing user registration controls.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows driver vulnerability allows local privilege escalation to SYSTEM, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allows privilege escalation and potential data deletion, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Outlook's improper input validation allows attackers to bypass Protected View and execute code remotely, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft .NET Framework vulnerability allows attackers to expose sensitive information and potentially execute code remotely, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow allowing local attackers to gain SYSTEM privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows kernel-mode driver vulnerability CVE-2024-35250 allows local privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CLFS driver heap-based buffer overflow allows local privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA WebVPN XSS vulnerability allows remote script injection via unspecified parameter.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows NTLMv2 hash disclosure via file open enables user impersonation and credential theft.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MSHTML platform contains a spoofing vulnerability actively exploited in the KEV list that causes confidentiality loss.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Management Console allows remote code execution via an unspecified vulnerability, enabling attackers to compromise systems without user interaction.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.