CVE-2026-35273
Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server allows authenticated attackers to execute remote code via deserialization of untrusted data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco FMC and SCC allow unauthenticated remote attackers to execute arbitrary Java code as root via deserialization of untrusted data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust Remote Support and Privileged Remote Access suffered an unpatched OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary system commands.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unauthenticated remote attacker can take over Oracle E-Business Suite's BI Publisher Integration component via HTTP, leading to full system compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint's improper authentication flaw allowed attackers to spoof network requests, view sensitive data, and modify information.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and Gateway suffered an out-of-bounds read vulnerability linked to ransomware that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical arbitrary write vulnerability in VMware ESXi allows sandbox escapes and is actively exploited by ransomware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware ESXi allows attackers with AD permissions to regain full host access by recreating a deleted admin group.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
NextGen Healthcare's Mirth Connect suffered a critical deserialization vulnerability allowing unauthenticated remote code execution, linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD memory disclosure flaw leaked secrets via invalid URL parsing in specific AnyConnect/WebVPN setups.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure, Policy Secure, and Neurons suffered an actively exploited SSRF vulnerability in their SAML component that bypassed authentication to access restricted resources.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authentication bypass flaw in Ivanti EPMM and MobileIron Core allowed attackers to access restricted resources, directly enabling ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.