Published Security3 min read
CISA sets August 14 clock on Metabase and Cisco bugs, August 25 for the Windows SYSTEM flaw
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CISA added three vulnerabilities affecting Metabase, Microsoft Windows and Cisco Secure Firewall to its Known Exploited Vulnerabilities (KEV) catalog. The report does not give affected version ranges, indicators of compromise, exploitation volume or attribution.
- Inclusion in the KEV catalog mandates that federal agencies address the security weaknesses by specific deadlines to mitigate risks.
- CVE-2026-20349 is a heap inspection flaw in Cisco Secure Firewall.
- CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
- CVE-2026-72898 is a critical SQL injection vulnerability in Metabase.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA has added three vulnerabilities affecting Metabase, Microsoft Windows and Cisco Secure Firewall to its Known Exploited Vulnerabilities catalog, according to Security Affairs as relayed by SC Media [1][15]. Listing is not advisory: it obliges federal agencies to fix the flaws by set deadlines, which CISA put at August 14, 2026 for the batch, with an extended August 25 date for the Windows bug [2][10][11].
That is eleven extra days for the one flaw that needs a foothold first [13]. CVE-2026-68820 is a use-after-free in the Windows Ancillary Function Driver for WinSock [4], and it yields SYSTEM-level code execution [9]. AFD is the classic local privilege escalation surface: it does not get an attacker in, it turns whatever they already have into full control of the host. The other two carry the August 14 date [14].
The Cisco entry, CVE-2026-20349, is described as a heap inspection flaw in Secure Firewall [3] leading to denial-of-service conditions [8]. Availability, not confidentiality. For a perimeter device that still matters more than the impact label suggests, because the failure mode is your enforcement point dropping out, but it is not data loss and it is not persistence.
The one to move on is Metabase. CVE-2026-72898 is a critical SQL injection [5] that Security Affairs describes as a zero-day allowing unauthenticated attackers to obtain administrator access and exfiltrate sensitive data [6]. Read that chain in order: no credentials, no phishing step, no local access, straight to admin on a business intelligence tool. Metabase sits by design on top of the warehouse, so administrator access is a query interface to whatever the instance was pointed at.
The split that decides who is exposed is hosting model. Metabase Cloud instances were patched automatically, while self-hosted deployments require action from the operator [7]. Cloud tenants had the work done for them and may not know the CVE applies to them at all. Self-hosted is where the unremediated population lives, and self-hosted analytics tends to be the kind of internal service that was stood up by a data team, exposed to a VPN or an internal load balancer, and then left alone. Asset inventories are frequently wrong about these.
The brief is thin on the parts operators would most want. It gives no affected version ranges, no indicators of compromise, no exploitation volume, and no attribution for any of the three [1][6]. Private organisations are advised to review the catalog and remediate regardless of the federal deadlines [12].
Watch whether Metabase exploitation details firm up, since unauthenticated pre-auth admin access on a widely self-hosted product is the sort of thing that gets commodified within days. Watch the August 25 Windows date: an extension on a local privilege escalation usually means patch risk, not low severity.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA added three vulnerabilities affecting Metabase, Microsoft Windows and Cisco Secure Firewall to its Known Exploited Vulnerabilities (KEV) catalog. The report does not give affected version ranges, indicators of compromise, exploitation volume or attribution.
- [2]
Inclusion in the KEV catalog mandates that federal agencies address the security weaknesses by specific deadlines to mitigate risks.
- [3]
CVE-2026-20349 is a heap inspection flaw in Cisco Secure Firewall.
- [4]
CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
- [5]
CVE-2026-72898 is a critical SQL injection vulnerability in Metabase.
- [6]
The Metabase vulnerability is described as a zero-day and allowed unauthenticated attackers to gain administrator access and exfiltrate sensitive data.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 14CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list
Additional citations
- Security Affairs, via SC Media brief
- SC Media



