According to Security Affairs, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities affecting Metabase, Microsoft Windows, and Cisco Secure Firewall to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates federal agencies to address these security weaknesses by specific deadlines to mitigate risks.The vulnerabilities added to the KEV catalog include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). The Metabase vulnerability, described as a zero-day, allowed unauthenticated attackers to gain administrator access and exfiltrate sensitive data. While Metabase Cloud instances were patched automatically, self-hosted deployments require immediate attention.The Cisco flaw could lead to denial-of-service conditions, and the Windows vulnerability allows for SYSTEM-level code execution. CISA has ordered federal agencies to remediate these vulnerabilities by August 14, 2026, with an extended deadline of August 25 for the Windows flaw. Private organizations are also strongly advised to review the KEV catalog and address these issues.Source: Security Affairs
Vulnerability Management
CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
