Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
252 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

990
Correlated CVEs
852
Under active attack
252
Critical
730
High
540
RCE
Exploited ⌖ KEV ⚡ RCE KEV 2026-06-12

CVE-2026-35273

Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#auth-bypass#data-breach#negligence
Exploited ⌖ KEV KEV 2026-04-22

CVE-2026-33825

Microsoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#privilege-escalation#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-04-13

CVE-2023-21529

Microsoft Exchange Server allows authenticated attackers to execute remote code via deserialization of untrusted data.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-03-19

CVE-2026-20131

Cisco FMC and SCC allow unauthenticated remote attackers to execute arbitrary Java code as root via deserialization of untrusted data.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#supply-chain#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2026-02-13

CVE-2026-1731

BeyondTrust Remote Support and Privileged Remote Access suffered an unpatched OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary system commands.

AFFECTS 1 Secure Remote Access

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-10-20

CVE-2025-61884

Oracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2025-10-06

CVE-2025-61882

An unauthenticated remote attacker can take over Oracle E-Business Suite's BI Publisher Integration component via HTTP, leading to full system compromise.

AFFECTS 10 Aconex for DefenseFederal Managed Cloud ServicesFusion CloudGovernment Cloud - Common ControlsOracle Cloud Infrastructure-Government CloudOracle Enterprise Performance Management (EPM) +4 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV KEV 2025-07-22

CVE-2025-49706

Microsoft SharePoint's improper authentication flaw allowed attackers to spoof network requests, view sensitive data, and modify information.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-07-22

CVE-2025-49704

Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2025-07-20

CVE-2025-53770

Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-07-10

CVE-2025-5777

Citrix NetScaler ADC and Gateway suffered an out-of-bounds read vulnerability linked to ransomware that was actively exploited in the wild.

AFFECTS 1 Citrix for Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2025-04-29

CVE-2025-31324

An unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment.

AFFECTS 2 SAP NS2 Cloud Intelligent EnterpriseSAP NS2 Secure Node with SuccessFactors Suite - DoD

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2025-04-08

CVE-2025-29824

A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-04-04

CVE-2025-22457

Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2025-03-11

CVE-2025-26633

An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-04

CVE-2025-22225

A critical arbitrary write vulnerability in VMware ESXi allows sandbox escapes and is actively exploited by ransomware.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce
Exploited ⌖ KEV ⚡ RCE KEV 2025-03-03

CVE-2018-8639

A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched#privilege-escalation#negligence
Exploited ⌖ KEV ⚡ RCE KEV 2025-01-13

CVE-2023-48365

Qlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.

AFFECTS 1 Qlik Cloud Government

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2025-01-08

CVE-2025-0282

Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-18

CVE-2024-0012

Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#rce#auth-bypass#negligence
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-18

CVE-2024-9474

Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-11-12

CVE-2024-49039

An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV ⚡ RCE KEV 2024-10-22

CVE-2024-38094

Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-10-15

CVE-2024-30088

A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-07-30

CVE-2024-37085

VMware ESXi allows attackers with AD permissions to regain full host access by recreating a deleted admin group.

AFFECTS 2 VMware Government Services (VGS)Workspace ONE

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#auth-bypass
Exploited ⌖ KEV KEV 2024-06-13

CVE-2024-26169

A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-05-20

CVE-2023-43208

NextGen Healthcare's Mirth Connect suffered a critical deserialization vulnerability allowing unauthenticated remote code execution, linked to ransomware attacks.

AFFECTS 1 Somnoware

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched#supply-chain#data-breach
Exploited ⌖ KEV KEV 2024-05-14

CVE-2024-30051

A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2024-04-12

CVE-2024-3400

Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks.

AFFECTS 2 GCS-HIGHPalo Alto Networks Government Cloud Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-03-26

CVE-2023-24955

An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-03-25

CVE-2021-44529

An unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-03-04

CVE-2024-21338

A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-02-15

CVE-2020-3259

Cisco ASA/FTD memory disclosure flaw leaked secrets via invalid URL parsing in specific AnyConnect/WebVPN setups.

AFFECTS 9 AppDynamics GovAPMCisco Cloudlock for GovernmentCisco Meraki for GovernmentCisco SD-WAN for GovernmentCisco Umbrella for GovernmentCisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) +3 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#data-breach
Exploited ⌖ KEV KEV 2024-02-13

CVE-2024-21412

An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-01-31

CVE-2024-21893

Ivanti Connect Secure, Policy Secure, and Neurons suffered an actively exploited SSRF vulnerability in their SAML component that bypassed authentication to access restricted resources.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched
Exploited ⌖ KEV KEV 2024-01-18

CVE-2023-35082

An authentication bypass flaw in Ivanti EPMM and MobileIron Core allowed attackers to access restricted resources, directly enabling ransomware campaigns.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#supply-chain#data-breach#unpatched#negligence
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2024-01-12

CVE-2024-21887

Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-10

CVE-2023-29357

An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#exploited-in-wild#unpatched#privilege-escalation#auth-bypass#rce
Exploited ⌖ KEV ⚡ RCE ◐ 0-DAY KEV 2024-01-10

CVE-2023-46805

Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise.

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
Exploited ⌖ KEV ⚡ RCE KEV 2024-01-08

CVE-2023-38203

Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

#ransomware#rce#exploited-in-wild#unpatched
◀ PREV PAGE 01 / 07 NEXT ▶