Illustrative image generated with AI
CISA Adds Three Exploited Vulnerabilities to the KEV Catalog
CISA adds three exploited vulnerabilities to KEV catalog: CVEs in Cisco ASA/FTD, Windows, and Metabase. Organizations must prioritize remediation.
Text generated by artificial intelligence, published without human review. AI transparency
The three flaws affect Cisco, Windows, and Metabase
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after identifying evidence of active exploitation:
- CVE-2026-20349, a heap inspection flaw in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD);
- CVE-2026-68820, a use-after-free vulnerability in Microsoft Windows’ Ancillary Function Driver for WinSock;
- CVE-2026-72898, an SQL injection vulnerability in the Metabase platform.
The exact affected product versions have not been disclosed.
Why KEV Catalog Inclusion Matters
Inclusion in the KEV catalog indicates that these vulnerabilities are not merely theoretical: there is evidence of real-world attacks or exploitation attempts.
The brief does not specify the operational impact of exploiting each CVE. In general, however, a compromise involving firewalls, Windows systems, or internet-facing platforms with database access could significantly affect the integrity and availability of impacted environments.
BOD 26-04: Prioritizing Security Updates Based on Risk identifies KEV vulnerabilities affecting publicly exposed assets as particularly high risk when they could enable full system control.
Guidance for Organizations
Federal Civilian Executive Branch (FCEB) agencies must comply with the management requirements established by BOD 26-04 and accelerate remediation of high-risk flaws.
In particular, they should:
- identify publicly exposed assets running Cisco ASA, Cisco FTD, Windows, or Metabase;
- prioritize KEV CVEs that could result in full control of the affected asset;
- apply available updates according to the respective vendors’ guidance;
- determine, before patching, whether threat actors have already compromised the systems.
No detailed patches, workarounds, or compromise indicators specific to the three vulnerabilities have been provided.
CISA also recommends that organizations outside the FCEB adopt a KEV-based risk management approach, treating these vulnerabilities as operational priorities rather than routine updates.
How New Vulnerabilities Are Nominated for the Catalog
CISA accepts submissions through the KEV Nomination Form. Each submission must include:
- the CVE identifier;
- evidence of exploitation;
- clear mitigation guidance.
Only vulnerabilities supported by sufficient evidence can be considered for possible inclusion in the catalog.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-72898CRITICAL10.0Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
- CVE-2026-20349HIGH8.6A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi
- CVE-2026-68820HIGH7.0Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
