type: incident ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [incident, cisa, kev, bod-26-04, zero-day, vuln-management, government] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalogue under BOD 26-04: CVE-2026-20349 (Cisco Secure Firewall ASA/FTD), CVE-2026-68820 (Windows afd.sys) and CVE-2026-72898 (Metabase).
Summary
CISA added three actively exploited vulnerabilities to its KEV Catalogue under BOD 26-04 on 2026-08-11:
- CVE-2026-20349 โ Cisco Secure Firewall ASA/FTD, an unauthenticated heap-inspection vulnerability allowing remote compromise
- CVE-2026-68820 โ Microsoft Windows Ancillary Function Driver for WinSock, the
afd.sysuse-after-free that is also this month's Patch Tuesday zero-day - CVE-2026-72898 โ Metabase, an unauthenticated SQL-injection giving administrator access, disclosed in the wild over the weekend
Federal civilian agencies must prioritise remediation; CISA urges all organisations to adopt the same risk-based patching posture.
Date
- Announced: 2026-08-11
Source
- CISA โ 2026-08-11
Related Pages
- Cve 2026 20349 Cisco Asa Ftd Heap Overflow, Cve 2026 68820 Afd Sys Winsock Uaf, Cve 2026 72898 Metabase Sql Injection โ the three KEV-added vulnerabilities
- Microsoft Patches 398 Flaws Including A Windows Driver Zero Day Under Active Att โ the same
afd.syszero-day in Patch Tuesday