Vulnerability Management

CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list

Magnifying glass red bug bounty, green binary code, identify and submit vulnerability reports

According to Security Affairs, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities affecting Metabase, Microsoft Windows, and Cisco Secure Firewall to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates federal agencies to address these security weaknesses by specific deadlines to mitigate risks.

The vulnerabilities added to the KEV catalog include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). The Metabase vulnerability, described as a zero-day, allowed unauthenticated attackers to gain administrator access and exfiltrate sensitive data. While Metabase Cloud instances were patched automatically, self-hosted deployments require immediate attention.

The Cisco flaw could lead to denial-of-service conditions, and the Windows vulnerability allows for SYSTEM-level code execution. CISA has ordered federal agencies to remediate these vulnerabilities by August 14, 2026, with an extended deadline of August 25 for the Windows flaw. Private organizations are also strongly advised to review the KEV catalog and address these issues.

Source: Security Affairs

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds