highOther

CISA KEV Catalog Update: Cisco ASA/FTD, Windows AFD, and Metabase Actively Exploited Vulnerabilities

First seen Aug 12, 2026 · Updated Aug 12, 2026

CISAKEVvulnerability-managementCiscoWindowsMetabaseSQL-injectionuse-after-freeheap-overflowBOD-26-04agent-relevant

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: a heap inspection flaw in Cisco Secure Firewall ASA/FTD, a use-after-free in the Windows Ancillary Function Driver for WinSock, and a SQL injection vulnerability in Metabase. Federal agencies are required under BOD 26-04 to remediate these on a prioritized timeline, and all organizations are strongly encouraged to patch given confirmed in-the-wild exploitation.

Technical Analysis

CVE-2026-20349 is a heap inspection vulnerability in Cisco Secure Firewall ASA and FTD software that could allow attackers to gain unauthorized access or trigger denial-of-service conditions on perimeter security appliances. CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock, a kernel-mode component, which is typically leveraged for local privilege escalation to SYSTEM following initial compromise. CVE-2026-72898 is a SQL injection vulnerability in Metabase, a widely used open-source business intelligence and data visualization tool, which could allow attackers to exfiltrate or manipulate backend database contents including credentials and analytics data. Organizations that deploy Metabase or similar BI tools as part of RAG pipelines or agent-facing analytics dashboards should treat this SQLi as a direct risk to any API keys, database credentials, or embedding stores accessible through that instance, and Windows hosts running AI agent frameworks are equally exposed to privilege escalation via the AFD flaw if initial access is achieved through other means.

Affected Systems

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software; Microsoft Windows systems with the Ancillary Function Driver for WinSock (afd.sys); Metabase BI platform (self-hosted deployments, version details per vendor advisory)

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in this CISA alert; refer to vendor advisories for Cisco, Microsoft, and Metabase for exploitation indicators

Remediation Steps

  1. 1

    Patch Cisco ASA/FTD

    Apply Cisco's security updates addressing CVE-2026-20349 on all Secure Firewall ASA and FTD deployments; verify firmware versions against Cisco's advisory.

  2. 2

    Patch Windows AFD Driver

    Deploy the Microsoft security update resolving CVE-2026-68820 in afd.sys across all affected Windows endpoints and servers, prioritizing internet-facing and high-privilege systems.

  3. 3

    Patch Metabase

    Upgrade Metabase instances to the version that remediates CVE-2026-72898; restrict database permissions used by Metabase connections to minimize SQLi blast radius.

  4. 4

    Follow BOD 26-04 Guidance

    FCEB agencies must remediate per CISA's Binding Operational Directive 26-04 timelines; all organizations should adopt the same risk-based prioritization for internet-exposed assets.

  5. 5

    Compromise Assessment

    Where these vulnerabilities were present on publicly exposed assets prior to patching, review logs for indicators of pre-patch compromise as required under BOD 26-04.

  6. 6

    Audit Agent-Connected BI/Analytics Tools

    Identify any Metabase or similar BI instances connected to AI agent pipelines, RAG data stores, or credential vaults, and rotate any credentials potentially exposed via the SQLi vector.

CVE / Advisory IDs

CVE-2026-20349CVE-2026-68820CVE-2026-72898

Industries Most Exposed

GovernmentFederal Civilian Executive BranchTechnologyFinanceHealthcareCritical InfrastructureCross-industry (BI/analytics users)

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.