CISA Adds Three Known Exploited Vulnerabilities to Catalog

By George Bailey   Published: 08/11/26   Updated: 08/11/26   5 min read
CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited flaws that map to very different owner groups: Cisco ASA/FTD edge devices, the Windows AFD.sys privilege-escalation bug now tied publicly to exploitation, and the Metabase SQL injection issue that can turn an analytics platform into a broader credential-and-data exposure problem.

That matters because KEV updates are not just awareness posts. They are a public signal that attackers are already using these paths, which means the real work is deciding which assets, teams, and emergency patch windows need to move first.

What CISA Added

CISA added these three CVEs to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation:

Those three entries do not belong in one generic bucket. One is an edge-device problem, one is a Windows post-compromise privilege-escalation problem, and one is an application-plus-data-access problem. That distinction is what should drive triage.

Why This KEV Update Matters

KEV additions matter because they collapse the usual debate about whether a flaw is merely severe on paper. Once a CVE lands in the KEV catalog, the question becomes whether your environment still exposes the path and how quickly you can reduce that exposure.

This particular update is useful because it touches three very common failure patterns. Cisco ASA/FTD can sit at the network edge and affect remote access or perimeter trust. CVE-2026-68820 matters wherever an attacker may already have code execution on Windows and wants SYSTEM. Metabase matters because analytics platforms often hold stored credentials, connected data sources, and administrative reach beyond the app itself.

How To Triage The Three Flaws

If you need a practical order of operations, start here:

That order can change based on your environment, but it is a better starting point than treating all three CVEs as equivalent.

What Defenders May Be Underestimating

The easy mistake is to read a KEV update as a patching task instead of an ownership test.

Most organizations do not struggle because they fail to understand the CVSS score. They struggle because they cannot answer basic questions fast enough: Do we run the affected product? Is it exposed? Who owns it? What else can it touch if exploited? Is there evidence someone may have used it before the patch landed?

That is especially true here. Cisco firewall ownership may sit with network teams, Metabase may sit with data or product teams, and Windows AFD.sys remediation may sit with endpoint or infrastructure teams. If those groups are not pulled into one timing conversation quickly, the KEV signal gets diluted into normal backlog behavior.

What Teams Should Do Next

Source Context

CyberExperts is using CISA as the primary reference for this article, with the analysis centered on the actual KEV entries CISA named: CVE-2026-20349, CVE-2026-68820, and CVE-2026-72898.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading