Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Flags Critical Cisco, Windows, and Metabase Flaws in KEV Catalog, Highlighting Active Exploits

CISA added three vulnerabilities—Cisco Secure Firewall ASA/FTD (CVE‑2026‑20349), Windows Winsock driver (CVE‑2026‑68820), and Metabase SQL injection (CVE‑2026‑72898)—to its Known Exploited Vulnerabilities catalog. These flaws enable denial‑of‑service, system‑level code execution, and unauthenticated data access, respectively, putting SOC 2‑compliant firms at risk of control failures and audit findings.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

CISA Adds Critical Cisco ASA, Windows Winsock, and Metabase SQL Injection Flaws to KEV Catalog

What It Is — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed three high‑severity vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE‑2026‑20349 – Cisco Secure Firewall ASA/FTD heap‑inspection flaw (CVSS 8.6).
  • CVE‑2026‑68820 – Microsoft Windows ancillary Winsock driver use‑after‑free (CVSS 7.0).
  • CVE‑2026‑72898 – Metabase unauthenticated SQL‑injection (CVSS 10.0).

Exploitability — All three are reported as actively exploited in the wild. Cisco and Metabase attacks have been observed in production environments; Microsoft notes “unproven” exploit maturity but acknowledges active exploitation attempts.

Affected Products – Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD); Microsoft Windows kernel‑mode Winsock driver (afd.sys); Metabase 1.58+ (both self‑hosted and Metabase Cloud).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: Each flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Unpatched assets constitute a control deficiency that auditors will flag.
  • Continuous Evidence: Demonstrating timely patching and remediation is essential evidence for a defensible SOC 2 audit trail.
  • Enterprise Buyer Expectations: Large customers now require proof that high‑severity KEV items are tracked, mitigated, and documented in a continuous‑compliance platform.

Recommended Actions

  • Prioritize Patch Deployment – Apply Cisco and Microsoft patches immediately; upgrade Metabase to a version that resolves CVE‑2026‑72898.
  • Map to SOC 2 Controls – Record the vulnerability, remediation date, and responsible owner against CC6.1 and CC7.1 in your control inventory.
  • Capture Automated Evidence – Use a continuous‑compliance tool to ingest patch‑management logs as immutable audit artifacts.
  • Validate Post‑Remediation – Conduct targeted scans to confirm the flaw is no longer exploitable.

Source: Security Affairs – CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to KEV catalog

📰 Original Source
https://securityaffairs.com/197110/hacking/u-s-cisa-adds-metabase-windows-and-cisco-secure-firewall-flaws-to-its-known-exploited-vulnerabilities-catalog.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →