Security Affairs
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains|50,000 Stripe Secrets Leaked in Public Code|U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog|Hackers Expose Data of 1.2 Million Heights Finance Customers|Project noRecognition: Teaching AI to Fool Surveillance Cameras|GitLab Patches Critical Unauthenticated GraphQL Vulnerability|U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog|New Mirai-Based Evooo1Bot Botnet Targets Linux Devices|SafePal Says 39,798 Customers Hit by Data Breach|LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected|Invisible AI Prompts Trigger Court Sanctions|McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen|Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains|50,000 Stripe Secrets Leaked in Public Code|U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog|Hackers Expose Data of 1.2 Million Heights Finance Customers|Project noRecognition: Teaching AI to Fool Surveillance Cameras|GitLab Patches Critical Unauthenticated GraphQL Vulnerability|U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog|New Mirai-Based Evooo1Bot Botnet Targets Linux Devices|SafePal Says 39,798 Customers Hit by Data Breach|LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected|Invisible AI Prompts Trigger Court Sanctions|McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated, […]

CISA Minnesota Attacks

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-20349 (CVSS score of 8.6) Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
  • CVE-2026-68820 (CVSS score of 7.0) Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
  • CVE-2026-72898 (CVSS score of 10.0) Metabase SQL Injection Vulnerability

CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated, remote attackers to crash affected devices and cause a denial-of-service condition. The flaw stems from insufficient error checking when processing HTTP requests. Attackers can exploit it by sending a specially crafted request to the Remote Access SSL VPN service, forcing the firewall to reload and disrupting network access.

CVE-2026-68820 is a use-after-free flaw in afd.sys, the kernel-mode driver that underpins the Windows Sockets API. CVE-2026-68820 is a Windows Winsock driver flaw that can allow attackers to execute code with SYSTEM-level privileges. Microsoft says it is actively exploited, although its CVSS assessment lists exploit maturity as “Unproven.”

CVE-2026-72898 Metabase SQL Injection Vulnerability allows an unauthenticated attacker inject arbitrary SQL straight into the Metabase application database.

“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above.” reads the company advisory. “We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability.”

That access is just the starting point. Once inside, the attacker could grab administrator rights over the whole instance, then pivot from there: changing application configuration, stealing stored credentials for every connected database, reading whatever data those connections could reach, and pulling it all out. For a business intelligence tool that’s typically plugged into a company’s most sensitive data warehouses, that’s close to a worst-case blast radius.

Metabase Cloud customers didn’t have to lift a finger. The company detected the attack, blocked the endpoint being abused, and patched it before most users even knew there was a problem, and cloud instances were already running the fixed version by the time the advisory went public. Self-hosted deployments are a different story entirely, and anyone running their own instance on an affected version needs to treat this as urgent, not routine.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by August 14, 2026, except for CVE-2026-68820, which must be addressed by August 25.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)