HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Advisory

CISA Adds Three Actively Exploited CVEs to KEV Catalog, Prompting Urgent Remediation

CISA added CVE‑2026‑20349 (Cisco ASA/FTD), CVE‑2026‑68820 (Windows WinSock), and CVE‑2026‑72898 (Metabase) to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Organizations must prioritize patching to stay compliant with BOD 26‑04 and maintain SOC 2 security criteria.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

CISA Adds Three Actively Exploited CVEs to KEV Catalog – Immediate Remediation Required

What It Is — The Cybersecurity and Infrastructure Security Agency (CISA) announced that three vulnerabilities with confirmed active exploitation have been added to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE‑2026‑20349 – Heap inspection flaw in Cisco Secure Firewall ASA & Firepower Threat Defense (FTD)
  • CVE‑2026‑68820 – Use‑after‑free in Microsoft Windows Ancillary Function Driver for WinSock
  • CVE‑2026‑72898 – SQL injection in Metabase (open‑source analytics platform)

Exploitability — All three are confirmed to be exploited in the wild; CISA’s inclusion in the KEV catalog signals that threat actors are already leveraging them. No public proof‑of‑concept is required for the advisory, but evidence of real‑world attacks exists.

Affected Products – Cisco Secure Firewall ASA/FTD appliances, Microsoft Windows (any version using the vulnerable WinSock driver), and Metabase installations (on‑premise or cloud‑hosted).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – Unpatched critical flaws constitute a failure of SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Mapping these CVEs to the relevant controls and documenting remediation provides concrete audit evidence.
  • Continuous Evidence – Demonstrating timely patch deployment and verification satisfies the “continuous monitoring” expectations of auditors and reduces the risk of a non‑conformity finding.
  • Enterprise Buyer Expectations – Federal agencies and large enterprises now require proof that KEV‑listed vulnerabilities are addressed; a robust control‑mapping process is a defensible way to meet that demand.

Recommended Actions

  • Inventory all assets running Cisco ASA/FTD, Windows WinSock driver, and Metabase.
  • Apply vendor‑supplied patches immediately; verify patch success with automated tools.
  • Update your vulnerability‑management workflow to flag any KEV‑catalog entries as “high‑priority” and capture remediation tickets as audit evidence.
  • Record remediation dates, patch versions, and validation results in a centralized compliance repository for SOC 2 auditors.

Source: CISA Advisory – KEV Catalog Update, Aug 11 2026

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →