THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to Metabase, Windows, and Cisco Secure Firewall to its Known Exploited Vulnerabilities catalog. The vulnerabilities include:
1. **CVE-2026-20349**: A heap inspection vulnerability in Cisco Secure Firewall that could allow remote attackers to cause a denial-of-service condition (CVSS score: 8.6).
2. **CVE-2026-68820**: A use-after-free flaw in Windows that can enable code execution with SYSTEM-level privileges (CVSS score: 7.0), which is currently under active exploitation.
3. **CVE-2026-72898**: An SQL injection vulnerability in Metabase that allows attackers to inject SQL commands into the application database (CVSS score: 10.0).
CISA requires federal agencies to address these issues by specific deadlines, with an emphasis on timely patching to protect against potential attacks. Organizations are advised to check the CISA catalog for compliance.