
CISA's latest KEV update is only useful if it changes what defenders do next. This one adds three actively exploited flaws that map to very different owner groups: Cisco ASA/FTD edge devices, the Windows AFD.sys privilege-escalation bug now tied publicly to exploitation, and the Metabase SQL injection issue that can turn an analytics platform into a broader credential-and-data exposure problem.
That matters because KEV updates are not just awareness posts. They are a public signal that attackers are already using these paths, which means the real work is deciding which assets, teams, and emergency patch windows need to move first.
Stay Current on Cyber Policy and Guidance
Track new CISA actions, regulations, guidance, and risk trends in a quick daily format.
Weekday mornings. Built from 100+ trusted cybersecurity sources.
What CISA Added
CISA added these three CVEs to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation:
- CVE-2026-20349: Cisco Secure Firewall ASA and Firewall Threat Defense heap-inspection vulnerability.
- CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock use-after-free vulnerability in
afd.sys. - CVE-2026-72898: Metabase SQL injection vulnerability.
Those three entries do not belong in one generic bucket. One is an edge-device problem, one is a Windows post-compromise privilege-escalation problem, and one is an application-plus-data-access problem. That distinction is what should drive triage.
Why This KEV Update Matters
KEV additions matter because they collapse the usual debate about whether a flaw is merely severe on paper. Once a CVE lands in the KEV catalog, the question becomes whether your environment still exposes the path and how quickly you can reduce that exposure.
This particular update is useful because it touches three very common failure patterns. Cisco ASA/FTD can sit at the network edge and affect remote access or perimeter trust. CVE-2026-68820 matters wherever an attacker may already have code execution on Windows and wants SYSTEM. Metabase matters because analytics platforms often hold stored credentials, connected data sources, and administrative reach beyond the app itself.
How To Triage The Three Flaws
If you need a practical order of operations, start here:
- First: Cisco ASA/FTD (
CVE-2026-20349) if you run affected internet-facing or business-critical remote-access infrastructure. Edge exposure usually gets patched before internal application cleanup because the blast radius of delay is wider. - Next: Metabase (
CVE-2026-72898) if you use self-hosted or broadly accessible analytics environments. The danger is not just the app bug; it is what the app can reach through stored credentials and connected databases. - Also urgent: Windows AFD.sys (
CVE-2026-68820) anywhere you are already worried about footholds, lateral movement, or privileged escalation on Windows hosts. This is the one to prioritize when your concern is post-compromise hardening and incident containment.
That order can change based on your environment, but it is a better starting point than treating all three CVEs as equivalent.
What Defenders May Be Underestimating
The easy mistake is to read a KEV update as a patching task instead of an ownership test.
Most organizations do not struggle because they fail to understand the CVSS score. They struggle because they cannot answer basic questions fast enough: Do we run the affected product? Is it exposed? Who owns it? What else can it touch if exploited? Is there evidence someone may have used it before the patch landed?
That is especially true here. Cisco firewall ownership may sit with network teams, Metabase may sit with data or product teams, and Windows AFD.sys remediation may sit with endpoint or infrastructure teams. If those groups are not pulled into one timing conversation quickly, the KEV signal gets diluted into normal backlog behavior.
What Teams Should Do Next
- Inventory whether you run affected Cisco ASA/FTD, Metabase, or Windows systems where
CVE-2026-68820matters, and assign named owners immediately instead of leaving this as a generic vuln-management ticket. - Prioritize internet-facing Cisco ASA/FTD and any externally reachable or widely used Metabase deployments ahead of normal patch backlog work.
- For Metabase, treat the issue as a possible credential-and-data exposure event, not just an application patch. Check what connected databases, saved credentials, or administrative functions the platform can reach.
- For Windows AFD.sys, review whether there are recent signs of suspicious local execution, privilege-escalation attempts, or incident activity on high-value Windows systems where an attacker might chain the flaw after initial access.
- Check whether the affected assets were already exposed before patching, because CISA's current directive language puts weight not just on patch speed but on whether you investigate possible compromise before the fix landed.
- Push a short stakeholder update that says which of the three CVEs you are exposed to, what is being patched first, and where there is still risk. That usually prevents the late scramble better than technical detail alone.
- Keep watching the primary source pages for revised scope, remediation guidance, or due-date expectations, especially if your internal teams need stronger justification for an emergency change window.
Source Context
CyberExperts is using CISA as the primary reference for this article, with the analysis centered on the actual KEV entries CISA named: CVE-2026-20349, CVE-2026-68820, and CVE-2026-72898.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief