CISA added three vulnerabilities affecting Cisco Secure Firewall, Microsoft Windows, and Metabase to its Known Exploited Vulnerabilities catalog on August 11, 2026.
CISA’s catalog separates vulnerabilities with evidence of active exploitation from the much larger stream of disclosed security flaws. Attackers are already using these flaws in the wild.
For U.S. federal civilian agencies, CISA assigned an August 14 remediation date to two of the three vulnerabilities. The Windows deadline is August 25. Those deadlines don’t bind private businesses, but they’re a strong priority signal if your environment uses any of the affected products.
Cisco firewall flaw can knock VPN access offline
The Cisco vulnerability, CVE-2026-20349, affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) software.
Cisco rates the flaw 8.6 out of 10 and has confirmed active exploitation. The Canadian Centre for Cyber Security also issued alert AL26-018 on August 13, 2026, warning that internet-accessible ASA and FTD systems with affected remote access VPN services are at risk.
The flaw sits in the Remote Access SSL VPN service. An unauthenticated remote attacker can send a crafted HTTP request to an affected device and cause it to reload unexpectedly, creating a denial-of-service condition.
For a business that relies on a Cisco firewall or VPN for remote work, the risk is operational too. A successful attack can interrupt access to the network employees use to do their jobs.
The affected configurations include devices running vulnerable ASA or FTD software with features such as SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access on FTD. Cisco says Cisco Secure Firewall Management Center is not affected by this vulnerability.
Cisco’s remediation path is fixed software or a hot fix, not a configuration-only fix. The Cyber Centre recommends identifying internet-facing ASA and FTD systems, checking whether the affected VPN services are enabled, reviewing logs for unexpected reloads or suspicious HTTP requests, and prioritizing exposed systems.
Metabase flaw can expose connected data
The Metabase vulnerability, CVE-2026-72898, affects Metabase, the open-source business intelligence and analytics platform.
Metabase rates the flaw 10.0 out of 10 and has confirmed active exploitation. The vulnerability lets an unauthenticated remote attacker inject SQL into the Metabase application database and gain administrator access to the instance.
From there, Metabase says an attacker could change application settings, steal stored credentials for connected databases, read data available through those connections, and export information.
The risk goes beyond a compromised analytics dashboard. If Metabase can reach business databases, a vulnerable Metabase instance can become a route toward the data behind the dashboards.
Metabase has released patched versions x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5. Organizations running earlier point releases in those branches should upgrade to the matching patched version or later.
If an organization can’t upgrade immediately, Metabase says temporarily blocking the /api/session/reset_password endpoint can reduce exposure. For instances where that endpoint was publicly accessible, Metabase recommends post-upgrade checks such as revoking active sessions, reviewing API keys and administrator accounts, rotating connected-database credentials, and checking activity logs for unauthorized access.
Windows flaw turns local access into higher privileges
The Microsoft vulnerability, CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock.
It is a use-after-free vulnerability that allows an authorized local attacker to elevate privileges. CISA lists it as actively exploited, and Microsoft addressed it through its August 2026 security updates.
This isn’t a remote entry point by itself. The attacker needs an existing foothold on the machine. But once an attacker has limited access, privilege escalation can help them take greater control, disable protections, move deeper into the system, or support the next stage of an attack.
For businesses managing Windows PCs or servers, the practical step is to verify that August security updates reached every supported device. Don’t assume automatic updates covered machines that have been offline, poorly managed, or missing from normal patch reporting.
CISA deadlines should affect your patch queue
Read CISA’s dates as risk signals, not private-sector compliance deadlines.
In this case, U.S. federal civilian agencies were given until August 14, 2026 to address the Cisco and Metabase vulnerabilities. The deadline for the Microsoft Windows vulnerability is August 25, 2026.
Private businesses don’t have to follow those federal deadlines. Still, CISA encourages all organizations to use risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities.
We saw the same timing problem with recent attacks against on-premises Microsoft SharePoint servers. Once attackers start exploiting a vulnerability, slow remediation gives them more time to find systems that haven’t been fixed.
What businesses should check now
Start with the products you actually use. If none of these systems are in your environment, there’s no reason to scramble. If one is present, the question becomes whether your version, configuration, and exposure match the affected conditions.
| Product | First question | Next action |
|---|---|---|
| Cisco ASA or FTD | Are affected remote access VPN or ZTNA services enabled on internet-facing systems? | Install Cisco’s fixed software or hot fix and review logs for reloads or suspicious SSL VPN requests. |
| Metabase | Are we running an affected self-hosted version? | Upgrade to the matching patched version or later, then review sessions, API keys, admin accounts, database credentials, and logs if the vulnerable endpoint was public. |
| Microsoft Windows | Did every supported PC and server receive the August 2026 security updates? | Check patch reporting for offline, unmanaged, or delayed devices instead of assuming automatic updates reached everything. |
If your IT is outsourced, you don’t need to turn the conversation into a broad cybersecurity review.
Ask one direct question:
Are we running anything affected by CVE-2026-20349, CVE-2026-72898, or CVE-2026-68820, and have the recommended fixes been applied?
That gives your IT provider or administrator something specific to verify.
Exploited flaws can’t sit in the normal backlog
Severity scores help, but exploitation changes the calculation. A lower-score flaw being used now can deserve faster action than a higher-score flaw that isn’t being exploited.
For affected environments, the practical response is calm and specific: confirm exposure, apply the vendor fix, and review logs where exploitation may have happened before the patch.
The longer an exploited vulnerability stays open, the more time attackers have to find systems still waiting for maintenance.
Frequently Asked Questions
What did CISA add to the KEV catalog on August 11, 2026?
CISA added three actively exploited vulnerabilities: CVE-2026-20349 affecting Cisco Secure Firewall ASA and FTD software, CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock, and CVE-2026-72898 affecting Metabase.
Do CISA deadlines apply to private businesses?
No. CISA’s KEV remediation deadlines apply to U.S. federal civilian agencies. Private businesses can still use those deadlines as a practical priority signal because the catalog focuses on vulnerabilities with evidence of active exploitation.
Is the Windows vulnerability remotely exploitable?
Public vulnerability descriptions say CVE-2026-68820 requires an authorized local attacker. In practice, that means an attacker needs some level of access first, then can use the flaw to elevate privileges on the affected Windows system.
What should a business ask its IT provider?
Ask whether the business runs anything affected by CVE-2026-20349, CVE-2026-72898, or CVE-2026-68820, and whether the vendor-recommended fixes have been applied. That question is specific enough for an IT provider to verify quickly.

We empower people to succeed through practical business information and essential services. If you’re looking for help with SEO, copywriting, or getting your online presence set up properly, you’re in the right place. If this piece helped, feel free to share it with someone who’d get value from it. Do you need help with something? Contact Us







