Skip to content
COOEY
CVE → FEDRAMP EXPOSURE
152 correlated CVEs

Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.

990
Correlated CVEs
852
Under active attack
252
Critical
730
High
540
RCE
Critical CVSS 10.0 NVD 2026-06-30

CVE-2026-13782

Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.9 NVD 2026-07-06

CVE-2026-40141

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited pr

AFFECTS 1 Secure Remote Access

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.8 NVD 2026-07-06

CVE-2026-40139

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, i

AFFECTS 1 Secure Remote Access

▸ DO  Critical severity — schedule patching of the affected products.

Critical ⚡ RCE ◐ 0-DAY CVSS 9.8 NVD 2026-06-30

CVE-2026-14104

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Remote code execution — patch the affected products on priority.

#rce#zero-day
Critical CVSS 9.8 NVD 2026-06-30

CVE-2026-13776

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.8 NVD 2026-06-30

CVE-2026-8452

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

AFFECTS 1 Citrix for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.8 NVD 2026-06-30

CVE-2026-13775

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.8 NVD 2026-06-30

CVE-2026-8655

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured

AFFECTS 1 Citrix for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical ⚡ RCE CVSS 9.8 NVD 2021-05-19

CVE-2017-17674

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code ex

AFFECTS 1 BMC Helix

▸ DO  Remote code execution — patch the affected products on priority.

#rce
Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-14106

Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-13781

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-13780

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-13785

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-14120

Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-14109

Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.6 NVD 2026-06-30

CVE-2026-14101

Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.3 NVD 2026-07-02

CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical CVSS 9.1 NVD 2026-07-08

CVE-2026-9074

IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality.

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

#unpatched#sql-injection#password-reset
Critical CVSS 9.1 NVD 2026-06-29

CVE-2026-11720

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-07-31

CVE-2026-14537

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-07-29

CVE-2026-14529

AFFECTS 5 IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-18

CVE-2026-12569

AFFECTS 1 PTC Cloud Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-09

CVE-2026-10523

AFFECTS 2 Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-09

CVE-2026-34691

AFFECTS 14 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +8 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-09

CVE-2026-47928

AFFECTS 8 Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign) +2 more

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10990

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10931

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10966

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11113

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10971

AFFECTS 6 Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11002

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11029

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10972

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-48567

AFFECTS 4 Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-11120

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-06-04

CVE-2026-10974

AFFECTS 2 Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-05-29

CVE-2025-41276

AFFECTS 1 Security Service Edge (Formerly McAfee MVISION)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-05-29

CVE-2025-41275

AFFECTS 1 Security Service Edge (Formerly McAfee MVISION)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-05-29

CVE-2025-41274

AFFECTS 1 Security Service Edge (Formerly McAfee MVISION)

▸ DO  Critical severity — schedule patching of the affected products.

Critical NVD 2026-05-29

CVE-2025-41273

AFFECTS 1 Security Service Edge (Formerly McAfee MVISION)

▸ DO  Critical severity — schedule patching of the affected products.

◀ PREV PAGE 01 / 04 NEXT ▶