CISA Adds Three Actively Exploited CVEs to KEV Catalog – Immediate Remediation Required
What It Is — The Cybersecurity and Infrastructure Security Agency (CISA) announced that three vulnerabilities with confirmed active exploitation have been added to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE‑2026‑20349 – Heap inspection flaw in Cisco Secure Firewall ASA & Firepower Threat Defense (FTD)
- CVE‑2026‑68820 – Use‑after‑free in Microsoft Windows Ancillary Function Driver for WinSock
- CVE‑2026‑72898 – SQL injection in Metabase (open‑source analytics platform)
Exploitability — All three are confirmed to be exploited in the wild; CISA’s inclusion in the KEV catalog signals that threat actors are already leveraging them. No public proof‑of‑concept is required for the advisory, but evidence of real‑world attacks exists.
Affected Products – Cisco Secure Firewall ASA/FTD appliances, Microsoft Windows (any version using the vulnerable WinSock driver), and Metabase installations (on‑premise or cloud‑hosted).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – Unpatched critical flaws constitute a failure of SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Mapping these CVEs to the relevant controls and documenting remediation provides concrete audit evidence.
- Continuous Evidence – Demonstrating timely patch deployment and verification satisfies the “continuous monitoring” expectations of auditors and reduces the risk of a non‑conformity finding.
- Enterprise Buyer Expectations – Federal agencies and large enterprises now require proof that KEV‑listed vulnerabilities are addressed; a robust control‑mapping process is a defensible way to meet that demand.
Recommended Actions
- Inventory all assets running Cisco ASA/FTD, Windows WinSock driver, and Metabase.
- Apply vendor‑supplied patches immediately; verify patch success with automated tools.
- Update your vulnerability‑management workflow to flag any KEV‑catalog entries as “high‑priority” and capture remediation tickets as audit evidence.
- Record remediation dates, patch versions, and validation results in a centralized compliance repository for SOC 2 auditors.