Security2 distinct publishers3 min readPublished Updated
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CISA has added three vulnerabilities affecting Metabase, Microsoft Windows and Cisco Secure Firewall to its Known Exploited Vulnerabilities catalog, according to Security Affairs as relayed by SC Media [1][15]. Listing is not advisory: it obliges federal agencies to fix the flaws by set deadlines, which CISA put at August 14, 2026 for the batch, with an extended August 25 date for the Windows bug [2][10][11].
That is eleven extra days for the one flaw that needs a foothold first [13]. CVE-2026-68820 is a use-after-free in the Windows Ancillary Function Driver for WinSock [4], and it yields SYSTEM-level code execution [9]. AFD is the classic local privilege escalation surface: it does not get an attacker in, it turns whatever they already have into full control of the host. The other two carry the August 14 date [14].
The Cisco entry, CVE-2026-20349, is described as a heap inspection flaw in Secure Firewall [3] leading to denial-of-service conditions [8]. Availability, not confidentiality. For a perimeter device that still matters more than the impact label suggests, because the failure mode is your enforcement point dropping out, but it is not data loss and it is not persistence.
The one to move on is Metabase. CVE-2026-72898 is a critical SQL injection [5] that Security Affairs describes as a zero-day allowing unauthenticated attackers to obtain administrator access and exfiltrate sensitive data [6]. Read that chain in order: no credentials, no phishing step, no local access, straight to admin on a business intelligence tool. Metabase sits by design on top of the warehouse, so administrator access is a query interface to whatever the instance was pointed at.
The split that decides who is exposed is hosting model. Metabase Cloud instances were patched automatically, while self-hosted deployments require action from the operator [7]. Cloud tenants had the work done for them and may not know the CVE applies to them at all. Self-hosted is where the unremediated population lives, and self-hosted analytics tends to be the kind of internal service that was stood up by a data team, exposed to a VPN or an internal load balancer, and then left alone. Asset inventories are frequently wrong about these.
The brief is thin on the parts operators would most want. It gives no affected version ranges, no indicators of compromise, no exploitation volume, and no attribution for any of the three [1][6]. Private organisations are advised to review the catalog and remediate regardless of the federal deadlines [12].
Watch whether Metabase exploitation details firm up, since unauthenticated pre-auth admin access on a widely self-hosted product is the sort of thing that gets commodified within days. Watch the August 25 Windows date: an extension on a local privilege escalation usually means patch risk, not low severity.
Ranked by verification strength, evidence, and original report placement.
CISA added three vulnerabilities affecting Metabase, Microsoft Windows and Cisco Secure Firewall to its Known Exploited Vulnerabilities (KEV) catalog. The report does not give affected version ranges, indicators of compromise, exploitation volume or attribution.
Inclusion in the KEV catalog mandates that federal agencies address the security weaknesses by specific deadlines to mitigate risks.
CVE-2026-20349 is a heap inspection flaw in Cisco Secure Firewall.
CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
CVE-2026-72898 is a critical SQL injection vulnerability in Metabase.
The Metabase vulnerability is described as a zero-day and allowed unauthenticated attackers to gain administrator access and exfiltrate sensitive data.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific but thinly sourced
The factual spine is precise, three named CVEs, three exposure classes, two dated deadlines, and it comes from a regulator action rather than a vendor announcement. But the cluster contains exactly one item, and that item is a secondary brief crediting Security Affairs with no primary CISA or vendor advisory attached, and no version ranges, IOCs or attribution to verify against.
Exploitation confirmed, exposure unquantified
KEV listing is itself real-world evidence that these flaws are being exploited and that a defined population, US federal agencies, is now compelled to remediate on a clock. The Metabase Cloud auto-patch shows part of the affected fleet has already moved. What is missing is any number: no exploitation volume, no victim count, no estimate of the self-hosted Metabase or Cisco Secure Firewall installed base still unpatched.
Roughly aligned, marginally underplayed
The brief does not inflate: it reports the KEV action, the deadlines and the mechanisms in flat language, with no vendor superlatives or projected impact. If anything it underplays, presenting an unauthenticated admin-access zero-day in a widely self-hosted BI tool in the same register as a firewall denial-of-service issue, and giving readers no scoping detail to judge their own exposure.
Regulator-driven, low commercial pull
The originating action is a government catalog addition and a compliance mandate, not a vendor or funding announcement, so there is little commercial incentive to overstate. The residual distortion is structural rather than promotional: an aggregation brief republishing another outlet's reporting has an incentive to publish fast and short, which plausibly explains the missing version ranges, IOCs and primary-source links, and no affected vendor is quoted.
Moderate on facts, weak on scope
Confidence in the enumerated CVEs, mechanisms and dates is reasonable because the claims are specific, mutually consistent and derive from a checkable regulator action. Confidence in anything beyond that, how widely exploited, which versions, how large the unpatched self-hosted population is, is low, because a single secondary brief is the only source and no dimension can be corroborated within the cluster.
security
CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive2 distinct publishers
security
A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories1 distinct publisher
security
CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass4 distinct publishers
build
CISA's exploited-vulnerability catalog now reaches the LLM gateway1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.