Jump to the main content block

【Vulnerability Alert】CISA Added 3 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/10-2026/08/16)

publish date : 2026-08-21 update date : 2026-08-21

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026081908082424 Publication Time 2026-08-19 08:38:24
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-19 08:38:24
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 3 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/10-2026/08/16)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000013

【CVE-2026-20349】Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability (CVSS v3.1: 8.6)
【Whether exploited by ransomware: Unknown】Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability. An unauthenticated remote attacker may exploit this vulnerability to cause the device to unexpectedly reload, resulting in a denial-of-service condition.

【CVE-2026-68820】Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (CVSS v3.1: 7.0)
【Whether exploited by ransomware: Unknown】Microsoft Windows Ancillary Function Driver for WinSock contains a Use-After-Free vulnerability. An authorized attacker may exploit this vulnerability to elevate privileges locally.

【CVE-2026-72898】Metabase SQL Injection Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】Metabase contains an SQL Injection vulnerability. An unauthenticated remote attacker may exploit this vulnerability to inject arbitrary SQL commands into the Metabase application database, thereby obtaining administrator privileges for the instance. After obtaining privileges, the attacker may further modify application settings, steal stored credentials for connected databases, read any data accessible through those connections, and export the data.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-20349】Please refer to the affected versions listed by the official vendor https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF

【CVE-2026-68820】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820

【CVE-2026-72898】Please refer to the affected versions listed by the official vendor https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf

[Recommended Actions]

【CVE-2026-20349】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF

【CVE-2026-68820】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820

【CVE-2026-72898】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: