# CISA adds Cisco, Windows, Metabase flaws to KEV

Published: 2026-08-11 · Severity: severe · Sectors: government-national
Canonical: https://vorant.io/reports/a1043494-a2ed-5b23-868d-f2bbdd81afe4/cisa-adds-cisco-windows-metabase-flaws-to-kev

> CISA added three actively exploited vulnerabilities in Cisco ASA/FTD, Windows AFD, and Metabase to its Known Exploited Vulnerabilities catalog, mandating federal remediation.

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with three new entries confirmed to be under active exploitation in the wild. The additions span network security appliances, operating system drivers, and business intelligence software: a heap inspection vulnerability in Cisco Secure Firewall ASA and FTD (CVE-2026-20349), a use-after-free flaw in the Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a SQL injection vulnerability in Metabase (CVE-2026-72898).

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that grant full post-exploitation control, and verify whether systems were compromised prior to patching. While the directive is binding only on FCEB agencies, CISA urges all organizations to adopt similar risk-based patching priorities given confirmed in-the-wild exploitation.

No further technical details, threat actor attribution, or campaign context were provided in this advisory. Organizations running Cisco ASA/FTD, affected Windows versions, or Metabase deployments should treat these as high-priority patches given the confirmed exploitation status.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20349 (KEV), CVE-2026-68820 (KEV), CVE-2026-72898 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a1043494-a2ed-5b23-868d-f2bbdd81afe4/cisa-adds-cisco-windows-metabase-flaws-to-kev.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
