securityaffairs.com 8/13/2026, 5:21:00 PM · external

CISA Flags Critical Flaws in Metabase, Windows and Cisco Firewall

CISA Flags Critical Flaws in Metabase, Windows and Cisco Firewall
Developing story vulnerability 20 articles tracked
CISA adds Cisco ASA/FTD and Metabase vulnerabilities to KEV catalog
CyberSIXT Evidence Panel

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to Metabase, Windows, and Cisco Secure Firewall to its Known Exploited Vulnerabilities catalog. The vulnerabilities include:

1. **CVE-2026-20349**: A heap inspection vulnerability in Cisco Secure Firewall that could allow remote attackers to cause a denial-of-service condition (CVSS score: 8.6).

2. **CVE-2026-68820**: A use-after-free flaw in Windows that can enable code execution with SYSTEM-level privileges (CVSS score: 7.0), which is currently under active exploitation.

3. **CVE-2026-72898**: An SQL injection vulnerability in Metabase that allows attackers to inject SQL commands into the application database (CVSS score: 10.0).

CISA requires federal agencies to address these issues by specific deadlines, with an emphasis on timely patching to protect against potential attacks. Organizations are advised to check the CISA catalog for compliance.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline