
CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited flaws that map to very different owner groups: Cisco ASA/FTD edge devices, the Windows AFD.sys privilege-escalation bug now tied publicly to exploitation, and the Metabase SQL injection issue that can turn an analytics platform into a broader credential-and-data exposure problem.
That matters because KEV updates are not just awareness posts. They are a public signal that attackers are already using these paths, which means the real work is deciding which assets, teams, and emergency patch windows need to move first.
What CISA Added
CISA added these three CVEs to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation:
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
- CVE-2026-20349: Cisco Secure Firewall ASA and Firewall Threat Defense heap-inspection vulnerability.
- CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock use-after-free vulnerability in
afd.sys. - CVE-2026-72898: Metabase SQL injection vulnerability.
Those three entries do not belong in one generic bucket. One is an edge-device problem, one is a Windows post-compromise privilege-escalation problem, and one is an application-plus-data-access problem. That distinction is what should drive triage.
Why This KEV Update Matters
KEV additions matter because they collapse the usual debate about whether a flaw is merely severe on paper. Once a CVE lands in the KEV catalog, the question becomes whether your environment still exposes the path and how quickly you can reduce that exposure.
This particular update is useful because it touches three very common failure patterns. Cisco ASA/FTD can sit at the network edge and affect remote access or perimeter trust. CVE-2026-68820 matters wherever an attacker may already have code execution on Windows and wants SYSTEM. Metabase matters because analytics platforms often hold stored credentials, connected data sources, and administrative reach beyond the app itself.
How To Triage The Three Flaws
If you need a practical order of operations, start here:
- First: Cisco ASA/FTD (
CVE-2026-20349) if you run affected internet-facing or business-critical remote-access infrastructure. Edge exposure usually gets patched before internal application cleanup because the blast radius of delay is wider. - Next: Metabase (
CVE-2026-72898) if you use self-hosted or broadly accessible analytics environments. The danger is not just the app bug; it is what the app can reach through stored credentials and connected databases. - Also urgent: Windows AFD.sys (
CVE-2026-68820) anywhere you are already worried about footholds, lateral movement, or privileged escalation on Windows hosts. This is the one to prioritize when your concern is post-compromise hardening and incident containment.
That order can change based on your environment, but it is a better starting point than treating all three CVEs as equivalent.
What Defenders May Be Underestimating
The easy mistake is to read a KEV update as a patching task instead of an ownership test.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Most organizations do not struggle because they fail to understand the CVSS score. They struggle because they cannot answer basic questions fast enough: Do we run the affected product? Is it exposed? Who owns it? What else can it touch if exploited? Is there evidence someone may have used it before the patch landed?
That is especially true here. Cisco firewall ownership may sit with network teams, Metabase may sit with data or product teams, and Windows AFD.sys remediation may sit with endpoint or infrastructure teams. If those groups are not pulled into one timing conversation quickly, the KEV signal gets diluted into normal backlog behavior.
What Teams Should Do Next
- Inventory whether you run affected Cisco ASA/FTD, Metabase, or Windows systems where
CVE-2026-68820matters, and assign named owners immediately instead of leaving this as a generic vuln-management ticket. - Prioritize internet-facing Cisco ASA/FTD and any externally reachable or widely used Metabase deployments ahead of normal patch backlog work.
- For Metabase, treat the issue as a possible credential-and-data exposure event, not just an application patch. Check what connected databases, saved credentials, or administrative functions the platform can reach.
- For Windows AFD.sys, review whether there are recent signs of suspicious local execution, privilege-escalation attempts, or incident activity on high-value Windows systems where an attacker might chain the flaw after initial access.
- Check whether the affected assets were already exposed before patching, because CISA's current directive language puts weight not just on patch speed but on whether you investigate possible compromise before the fix landed.
- Push a short stakeholder update that says which of the three CVEs you are exposed to, what is being patched first, and where there is still risk. That usually prevents the late scramble better than technical detail alone.
- Keep watching the primary source pages for revised scope, remediation guidance, or due-date expectations, especially if your internal teams need stronger justification for an emergency change window.
Source Context
CyberExperts is using CISA as the primary reference for this article, with the analysis centered on the actual KEV entries CISA named: CVE-2026-20349, CVE-2026-68820, and CVE-2026-72898.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Coder’s registry infrastructure compromised to push malicious modules
The Coder incident is a supply-chain lesson in miniature: once attackers can tamper with trusted module distribution, defenders are no longer verifying...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The useful lesson in this campaign is not that Node.js is bad. It is that adversaries keep choosing legitimate runtimes defenders already...
HPE patches critical ArubaOS-CX remote code execution flaw
ArubaOS-CX deserves attention because switching software rarely gets treated with the same urgency as identity or edge security until exploitation arrives. A...
The 5-Minute Cyber Brief: September 9, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.