Vulnerability Management CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list August 14, 2026 Share By SC Staff (Adobe Stock) According to Security Affairs, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities affecting Metabase, Microsoft Windows, and Cisco Secure Firewall to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates federal agencies to address these security weaknesses by specific deadlines to mitigate risks. The vulnerabilities added to the KEV catalog include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). The Metabase vulnerability, described as a zero-day, allowed unauthenticated attackers to gain administrator access and exfiltrate sensitive data. While Metabase Cloud instances were patched automatically, self-hosted deployments require immediate attention. The Cisco flaw could lead to denial-of-service conditions, and the Windows vulnerability allows for SYSTEM-level code execution. CISA has ordered federal agencies to remediate these vulnerabilities by August 14, 2026, with an extended deadline of August 25 for the Windows flaw. Private organizations are also strongly advised to review the KEV catalog and address these issues. Source: Security Affairs SC Staff Related Vulnerability Management Spectre vulnerabilities found on commercial RISC-V chips SC Staff August 13, 2026 Academic researchers from the CISPA Helmholtz Center for Information Security and KU Leuven have demonstrated that commercially available out-of-order RISC-V processors, specifically the SiFive P550 and T-Head Xuantie C910/C920, are vulnerable to all major Spectre variants. Vulnerability Management Zoom vulnerabilities could enable RCE against meeting participants Laura French August 12, 2026 The flaws involving Zoom’s screenshare annotation feature were discovered with AI assistance. Vulnerability Management Cisco warns of 7 ClamAV flaws impacting Secure Endpoint Connector SC Staff August 12, 2026 The vulnerabilities, identified as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, impact ClamAV's parsers for various file formats. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds