CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list
Overview
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Cisco Secure Firewall, Windows Ancillary Function Driver for WinSock, Metabase
- Action Required: Organizations should apply patches or updates provided by Cisco for the Secure Firewall, Microsoft for the Windows Ancillary Function Driver, and Metabase for the SQL injection vulnerability.
- Timeline: Newly disclosed
Original Article Summary
The vulnerabilities added to the KEV catalog include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898).
Impact
Cisco Secure Firewall, Windows Ancillary Function Driver for WinSock, Metabase
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply patches or updates provided by Cisco for the Secure Firewall, Microsoft for the Windows Ancillary Function Driver, and Metabase for the SQL injection vulnerability. Regularly checking for software updates and implementing security best practices, such as restricting access and monitoring for unusual activity, is also recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, CVE, Microsoft, and 4 more.