Category: CISA Advisories
Have you ever locked your office door, checked it twice, and then realized a window was still open?
That is what vulnerability management can feel like. You may have strong passwords, antivirus protection, and a firewall in place: but one unpatched system can still give an attacker a way inside.
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 11, 2026:
- CVE-2026-72898 : Metabase SQL injection
- CVE-2026-68820 : Microsoft Windows AFD WinSock use-after-free
- CVE-2026-20349 : Cisco Secure Firewall ASA/FTD heap inspection
Under BOD 26-04, the remediation deadline for Metabase and Cisco firewalls was August 14, 2026. That deadline has passed.
The Windows deadline is August 25, 2026.
If your business uses any of these technologies, now is the time to verify your exposure: not next week, and not after an outage.
Why these CISA listings matter
CISA’s KEV catalog is not simply a list of theoretical software bugs. It tracks vulnerabilities that attackers are known to be exploiting in real-world operations.
That changes the conversation.
A vulnerability may have existed quietly for months. Once it appears in the KEV catalog, you should treat it like a broken lock that someone is actively trying to open. You need to identify affected systems, apply the vendor’s fix, review logs, and determine whether the vulnerability may already have been used against you.
BOD 26-04 applies directly to federal civilian agencies, but private businesses should still use these deadlines as a serious risk-management benchmark.
And here’s the important part: the three vulnerabilities affect different layers of your technology environment.
One can expose business intelligence data. One can elevate access on a Windows computer. One can repeatedly knock a remote-access firewall offline.
CVE-2026-72898: Metabase SQL injection

Metabase is a business intelligence and analytics platform that helps organizations ask questions about their data, build dashboards, and share reports.
CVE-2026-72898 is an unauthenticated SQL injection vulnerability. SQL injection means an attacker can manipulate database commands through specially crafted input. In this case, a remote attacker may be able to inject SQL through the password-reset process without logging in first.
That is the frightening part.
An attacker who gains administrator access to a Metabase instance may be able to:
- Change Metabase configuration
- Access sensitive application data
- Steal stored credentials for connected databases
- Read information available through those database connections
- Export business data
If your Metabase server is reachable from the public internet, the risk is especially urgent. Even if Metabase itself is not your company’s primary database, it may have permission to connect to accounting, customer, inventory, or operational systems.
That is sensitive information leaving the safety of your business.
What to do about the Metabase vulnerability
Start by identifying every self-hosted Metabase deployment in your environment, including cloud-hosted virtual machines and systems managed by third parties.
Then:
- Upgrade to the latest patched release recommended in the Metabase security advisory.
- If you cannot upgrade immediately, restrict or block access to the password-reset endpoint through your WAF or reverse proxy.
- Review Metabase logs for suspicious password-reset requests and unusual administrator activity.
- Look for unexpected administrator accounts, API keys, sessions, queries, or exports.
- Revoke active sessions if the instance was publicly reachable before patching.
- Rotate credentials for databases connected to Metabase.
- Review database and data warehouse logs for unauthorized access.
Do not assume that patching alone closes the incident. If an exposed instance was vulnerable, you also need to ask whether someone used it before the update.
CVE-2026-68820: Windows AFD WinSock use-after-free

CVE-2026-68820 affects the Windows Ancillary Function Driver for WinSock, commonly called AFD.sys.
A use-after-free vulnerability occurs when software continues using a section of memory after that memory has already been released. Imagine checking out a book from a library, returning it, and then continuing to write notes in the same copy. The system believes the resource is available for another use, but the old process still has a reference to it.
In Windows, this flaw can allow an authorized local attacker to elevate privileges.
In plain language, an attacker who already has a foothold on a workstation or server may be able to move from ordinary user access to much higher privileges: potentially SYSTEM-level control. That can allow the attacker to disable security tools, access protected files, install malware, or move further through your network.
This is not the same as an unauthenticated internet attack. However, attackers frequently use phishing, stolen credentials, malicious files, or remote access compromise to gain that initial foothold. A local privilege escalation bug can then become the next step in a larger attack.
What to do about the Windows vulnerability
CISA’s BOD 26-04 deadline is August 25, 2026. Do not wait for the deadline.
Apply Microsoft’s August 11, 2026 security updates: or a later cumulative update that includes the fix: to affected Windows systems. Use your normal update platform, such as Windows Update for Business, Intune, Configuration Manager, or WSUS.
Then verify that:
- The update installed successfully.
- The system has been rebooted.
- No reboot is still pending.
- The affected Windows build is current according to Microsoft’s security advisory.
- Endpoint detection and response tools show no suspicious privilege escalation.
Pay particular attention to systems used for remote access, accounting, administration, file storage, and other sensitive business functions.
A patch that has been downloaded but not installed is not protection. A patch that has been installed but still requires a reboot may not be protection either.
CVE-2026-20349: Cisco Secure Firewall ASA/FTD heap inspection

CVE-2026-20349 affects Cisco Secure Firewall Adaptive Security Appliance software and Secure Firewall Threat Defense software.
The vulnerability exists in the Remote Access SSL VPN service. An unauthenticated remote attacker can send a specially crafted HTTP request to an affected device, causing it to reload unexpectedly.
The primary impact is denial of service.
Think about what happens if your front-door security system repeatedly shuts itself down. Employees may lose remote access, site-to-site operations may be disrupted, and the firewall may repeatedly reboot while your team tries to understand what is happening.
If that is not enough to worry you, a VPN outage can also create confusion during a broader attack. Users may report that they cannot connect while monitoring teams are forced to determine whether the problem is a configuration issue, hardware failure, or active exploitation.
CISA’s deadline for this vulnerability was August 14, 2026. That date has passed.
What to do about the Cisco vulnerability
Cisco’s advisory states that upgrading to a fixed software release is the required remediation. There is no configuration workaround that fully addresses the flaw.
Your team should:
- Inventory all ASA and FTD devices.
- Record the exact software version and enabled remote-access features.
- Use the Cisco security advisory to identify the correct fixed release.
- Upgrade exposed devices as soon as possible.
- If an immediate upgrade is impossible, consult your security provider about temporarily disabling or restricting remote-access VPN services.
- Preserve crashinfo files, firewall logs, VPN logs, and external syslog data before rebooting when practical.
- Monitor for unexpected reloads, repeated VPN failures, and sudden drops in active sessions.
Do not expose management interfaces to the public internet while you are addressing this issue. Restrict administrative access to trusted networks and authorized personnel.
Your immediate response checklist
So, what can you do today?
Use this short checklist:
- Identify exposure. Find every Metabase deployment, Windows system, and Cisco ASA/FTD device in your environment.
- Prioritize internet-facing systems. Publicly reachable Metabase servers and VPN gateways require immediate attention.
- Patch or upgrade. Apply vendor fixes and complete required reboots.
- Apply temporary controls. Restrict vulnerable endpoints or disable exposed services when safe and necessary.
- Review evidence. Check logs, administrator accounts, VPN events, endpoint alerts, and unusual data access.
- Rotate credentials. Change database, administrator, API, and service credentials if compromise is possible.
- Document remediation. Record affected assets, update versions, dates, and verification results.
Most importantly, do not treat the August 14 deadline as a reason to stop once the date has passed. An overdue deadline means the risk requires immediate correction.
How Platinum Web Services can help
Small business owners should not have to investigate every security advisory alone.
Platinum Web Services helps businesses identify vulnerable systems, prioritize urgent updates, secure remote access, review endpoint protection, and build a proactive patching strategy. Our cybersecurity solutions, managed IT services, and SOC services are designed to reduce uncertainty and keep your technology operating securely.
If you are unsure whether your business is affected, contact Platinum Web Services for help reviewing your environment.
You lock your doors to protect your business. Patching these vulnerabilities is how you make sure the windows are closed, too.


0 Comments