U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini August 13, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-20349 (CVSS score of 8.6) Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
  • CVE-2026-68820 (CVSS score of 7.0) Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
  • CVE-2026-72898 (CVSS score of 10.0) Metabase SQL Injection Vulnerability

CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated, remote attackers to crash affected devices and cause a denial-of-service condition. The flaw stems from insufficient error checking when processing HTTP requests. Attackers can exploit it by sending a specially crafted request to the Remote Access SSL VPN service, forcing the firewall to reload and disrupting network access.

CVE-2026-68820 is a use-after-free flaw in afd.sys, the kernel-mode driver that underpins the Windows Sockets API. CVE-2026-68820 is a Windows Winsock driver flaw that can allow attackers to execute code with SYSTEM-level privileges. Microsoft says it is actively exploited, although its CVSS assessment lists exploit maturity as “Unproven.”

CVE-2026-72898 Metabase SQL Injection Vulnerability allows an unauthenticated attacker inject arbitrary SQL straight into the Metabase application database.

“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above.” reads the company advisory. “We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability.”

That access is just the starting point. Once inside, the attacker could grab administrator rights over the whole instance, then pivot from there: changing application configuration, stealing stored credentials for every connected database, reading whatever data those connections could reach, and pulling it all out. For a business intelligence tool that’s typically plugged into a company’s most sensitive data warehouses, that’s close to a worst-case blast radius.

Metabase Cloud customers didn’t have to lift a finger. The company detected the attack, blocked the endpoint being abused, and patched it before most users even knew there was a problem, and cloud instances were already running the fixed version by the time the advisory went public. Self-hosted deployments are a different story entirely, and anyone running their own instance on an affected version needs to treat this as urgent, not routine.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by August 14, 2026, except for CVE-2026-68820, which must be addressed by August 25.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



you might also like

leave a comment