Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [incident, cisa, kev, bod-26-04, zero-day, vuln-management, government] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalogue under BOD 26-04: CVE-2026-20349 (Cisco Secure Firewall ASA/FTD), CVE-2026-68820 (Windows afd.sys) and CVE-2026-72898 (Metabase).

Summary

CISA added three actively exploited vulnerabilities to its KEV Catalogue under BOD 26-04 on 2026-08-11:

  • CVE-2026-20349 โ€” Cisco Secure Firewall ASA/FTD, an unauthenticated heap-inspection vulnerability allowing remote compromise
  • CVE-2026-68820 โ€” Microsoft Windows Ancillary Function Driver for WinSock, the afd.sys use-after-free that is also this month's Patch Tuesday zero-day
  • CVE-2026-72898 โ€” Metabase, an unauthenticated SQL-injection giving administrator access, disclosed in the wild over the weekend

Federal civilian agencies must prioritise remediation; CISA urges all organisations to adopt the same risk-based patching posture.

Date

  • Announced: 2026-08-11

Source

  • CISA โ€” 2026-08-11

Related Pages