CISA Adds Critical Vulnerabilities to Known Exploited Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities catalog. These vulnerabilities, if exploited, can allow attackers to execute code with SYSTEM-level privileges, crash affected devices, or inject arbitrary SQL into a database.
The CISA has identified three vulnerabilities: CVE-2026-20349 in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD), CVE-2026-68820 in Microsoft Windows Ancillary Function Driver for WinSock, and CVE-2026-72898 in Metabase SQL Injection Vulnerability.
CVE-2026-20349 allows attackers to crash affected devices and cause a denial-of-service condition. CVE-2026-68820 is a use-after-free flaw that can allow attackers to execute code with SYSTEM-level privileges, while CVE-2026-72898 enables attackers to inject arbitrary SQL into the Metabase application database.
Experts recommend that private organizations review the CISA catalog and address the vulnerabilities in their infrastructure. The CISA has ordered federal agencies to fix the flaws by August 14, 2026, except for CVE-2026-68820, which must be addressed by August 25.