Ethical Hacking News
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog due to their potential for exploitation by hackers. These high-priority targets highlight the ongoing threat landscape and emphasize the need for organizations to prioritize vulnerability management and patching.
CISA has added three high-priority vulnerabilities (CVE-2026-20349, CVE-2026-68820, and CVE-2026-72898) to its Known Exploited Vulnerabilities catalog.The vulnerabilities have the potential to impact system security and are being actively exploited by hackers.CVE-2026-20349 allows remote attackers to crash Cisco Secure Firewall devices via a denial-of-service condition.CVE-2026-68820 allows attackers to execute code with SYSTEM-level privileges on Windows systems.CVE-2026-72898 is an SQL injection vulnerability in Metabase Cloud that grants administrative access.Private organizations are advised to review the KEV catalog and address these vulnerabilities as soon as possible.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added three vulnerabilities - CVE-2026-20349, CVE-2026-68820, and CVE-2026-72898 - to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities have been identified as high-priority targets for hackers due to their potential impact on the security of various systems.
The first vulnerability, CVE-2026-20349, is a heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD). This vulnerability allows unauthenticated, remote attackers to crash affected devices and cause a denial-of-service condition. Attackers can exploit this flaw by sending a specially crafted request to the Remote Access SSL VPN service, forcing the firewall to reload and disrupting network access.
The second vulnerability, CVE-2026-68820, is a use-after-free flaw in the Windows Sockets API kernel-mode driver. This vulnerability allows attackers to execute code with SYSTEM-level privileges, potentially leading to elevated access to sensitive data. Microsoft has confirmed that this vulnerability is actively being exploited.
The third and most critical vulnerability, CVE-2026-72898, is an SQL injection vulnerability in Metabase Cloud. This vulnerability allows unauthenticated attackers to inject arbitrary SQL into the application's database, effectively granting them administrative access to the system. The company advisory states that the attack was detected and patched before it could cause significant damage.
It is worth noting that both self-hosted deployments of Metabase Cloud and Windows systems are affected by these vulnerabilities, highlighting the importance of timely patching and vulnerability management for organizations. CISA has ordered federal agencies to address the identified vulnerabilities by specific dates, with some exceptions, in order to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend that private organizations review the KEV catalog and address the vulnerabilities in their infrastructure as soon as possible. The growing number of known exploited vulnerabilities highlights the need for proactive measures to ensure the security of digital systems.
The addition of these three vulnerabilities to the KEV catalog serves as a reminder of the ongoing threat landscape and the importance of staying vigilant in protecting against cyber threats. Organizations must prioritize vulnerability management, patching, and incident response to minimize the impact of such vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Metabase-Windows-and-Cisco-Secure-Firewall-Flaws-to-its-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml
https://securityaffairs.com/197110/uncategorized/u-s-cisa-adds-metabase-windows-and-cisco-secure-firewall-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-20349
https://www.cvedetails.com/cve/CVE-2026-20349/
https://nvd.nist.gov/vuln/detail/CVE-2026-68820
https://www.cvedetails.com/cve/CVE-2026-68820/
https://nvd.nist.gov/vuln/detail/CVE-2026-72898
https://www.cvedetails.com/cve/CVE-2026-72898/
Published: Thu Aug 13 13:40:52 2026 by llama3.2 3B Q4_K_M