Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Critical
CVSS 10.0
NVD
2026-06-30
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.9
NVD
2026-07-06
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited pr
AFFECTS 1
Secure Remote Access
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-07-06
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, i
AFFECTS 1
Secure Remote Access
▸ DO Critical severity — schedule patching of the affected products.
Critical
⚡ RCE
◐ 0-DAY
CVSS 9.8
NVD
2026-06-30
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Remote code execution — patch the affected products on priority.
#rce#zero-day
Critical
CVSS 9.8
NVD
2026-06-30
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AFFECTS 1
Citrix for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.8
NVD
2026-06-30
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured
AFFECTS 1
Citrix for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
⚡ RCE
CVSS 9.8
NVD
2021-05-19
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code ex
AFFECTS 1
BMC Helix
▸ DO Remote code execution — patch the affected products on priority.
#rce
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.6
NVD
2026-06-30
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.3
NVD
2026-07-02
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
CVSS 9.1
NVD
2026-07-08
IBM API Connect versions 10.0.8.0–10.0.8.9 and 12.1.0.0–12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality.
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
#unpatched#sql-injection#password-reset
Critical
CVSS 9.1
NVD
2026-06-29
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.
When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-07-31
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-07-29
AFFECTS 5
IBM Cloud for GovernmentIBM Federal HR CloudIBM Maximo and TRIRIGA on Cloud for U.S. FederalMaaS360 Enterprise Mobility ManagementSmartCloud for Government
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-18
AFFECTS 1
PTC Cloud Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-09
AFFECTS 2
Ivanti Neurons for ITSM (Formerly Service Manager)Ivanti Neurons for MDM (Formerly MobileIron)
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-09
AFFECTS 14
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+8 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-09
AFFECTS 8
Adobe Acrobat Sign for GovernmentAdobe AnalyticsAdobe CampaignAdobe Connect Managed Services (ACMS-GC)Adobe Creative Cloud for EnterpriseAdobe Document Cloud (PDF Services & Adobe Sign)
+2 more
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 6
Azure Commercial CloudAzure Government (includes Dynamics 365)Google Services (Google Cloud Platform Products and underlying Infrastructure)Google WorkspaceMicrosoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-06-04
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-29
AFFECTS 1
Security Service Edge (Formerly McAfee MVISION)
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-29
AFFECTS 1
Security Service Edge (Formerly McAfee MVISION)
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-29
AFFECTS 1
Security Service Edge (Formerly McAfee MVISION)
▸ DO Critical severity — schedule patching of the affected products.
Critical
NVD
2026-05-29
AFFECTS 1
Security Service Edge (Formerly McAfee MVISION)
▸ DO Critical severity — schedule patching of the affected products.