Executive Summary
On August 11, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities are: CVE-2026-20349 affecting Cisco Secure Firewall ASA and FTD, CVE-2026-68820 in Microsoft Windows Ancillary Function Driver for WinSock, and CVE-2026-72898 in Metabase. These vulnerabilities are frequently targeted by malicious actors and pose significant risks to federal enterprises.
CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog. While BOD 26-04 applies to federal agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and address these vulnerabilities promptly.
Why This Matters Now
The addition of these vulnerabilities to the KEV Catalog underscores the immediate threat they pose due to active exploitation. Organizations must act swiftly to mitigate these risks to prevent potential breaches and data loss.
Attack Path Analysis
An attacker exploited vulnerabilities in Cisco ASA, Windows Ancillary Function Driver, and Metabase to gain initial access, escalate privileges, move laterally, establish command and control, exfiltrate data, and impact systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker exploited CVE-2026-20349 in Cisco ASA, CVE-2026-68820 in Windows Ancillary Function Driver, and CVE-2026-72898 in Metabase to gain unauthorized access.
Related CVEs
CVE-2026-20349
CVSS 8.6A vulnerability in the REST API of Cisco Catalyst Center allows an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user.
Affected Products:
Cisco Cisco Catalyst Center – 1.4.0.0, 2.1.1.0, 2.1.1.3, 2.1.2.0, 2.1.2.3, 2.1.2.4, 2.1.2.5, 2.2.1.0, 2.1.2.6, 2.2.2.0, 2.2.2.1, 2.2.2.3, 2.1.2.7, 2.2.1.3, 2.2.3.0, 2.2.2.4, 2.2.2.5, 2.2.3.3, 2.2.2.7, 2.2.2.6, 2.2.2.8, 2.2.3.4, 2.1.2.8, 2.3.2.1, 2.3.2.1-AIRGAP, 2.3.2.1-AIRGAP-CA, 2.2.3.5, 2.3.3.0, 2.3.3.3, 2.3.3.1-AIRGAP, 2.3.3.1, 2.3.2.3, 2.3.3.3-AIRGAP, 2.2.3.6, 2.2.2.9, 2.3.3.0-AIRGAP, 2.3.3.3-AIRGAP-CA, 2.3.3.4, 2.3.3.4-AIRGAP, 2.3.3.4-AIRGAP-MDNAC, 2.3.3.4-HF1, 2.3.4.0, 2.3.3.5, 2.3.3.5-AIRGAP
Exploit Status:
exploited in the wildCVE-2026-68820
CVSS 7A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock allows an attacker to execute arbitrary code.
Affected Products:
Microsoft Windows – 10, 11, Server 2019, Server 2022
Exploit Status:
exploited in the wildCVE-2026-72898
CVSS 10A SQL injection vulnerability in Metabase allows an attacker to execute arbitrary SQL commands.
Affected Products:
Metabase Metabase – 0.45.0, 0.45.1, 0.45.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Exploitation for Privilege Escalation
Valid Accounts
OS Credential Dumping
Remote System Discovery
Remote Services
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory remediation under BOD 26-04 for Cisco ASA/FTD, Microsoft Windows, and Metabase vulnerabilities actively exploited by threat actors.
Financial Services
Banking infrastructure using Cisco firewalls and Windows systems vulnerable to heap inspection and use-after-free exploits requiring immediate zero trust segmentation implementation.
Health Care / Life Sciences
Healthcare networks with Cisco security appliances face HIPAA compliance risks from active exploits targeting firewall vulnerabilities and database SQL injection attacks.
Information Technology/IT
IT service providers managing client networks through vulnerable Cisco ASA/FTD and Metabase systems require urgent patching to prevent lateral movement exploitation.
Sources
- CISA Adds Three Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalogVerified
- NVD - CVE-2026-20349https://nvd.nist.gov/vuln/detail/CVE-2026-20349Verified
- NVD - CVE-2026-68820https://nvd.nist.gov/vuln/detail/CVE-2026-68820Verified
- NVD - CVE-2026-72898https://nvd.nist.gov/vuln/detail/CVE-2026-72898Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it could have significantly constrained the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial exploitation may still occur, CNSF would likely limit the attacker's ability to leverage compromised systems to access other workloads.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges across different workloads by enforcing strict access controls.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely restrict the attacker's ability to move laterally by controlling and monitoring internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized command and control channels by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely restrict unauthorized data exfiltration by enforcing strict outbound traffic policies.
While initial compromise may still occur, CNSF would likely limit the attacker's ability to propagate ransomware across workloads, reducing overall impact.
Impact at a Glance
Affected Business Functions
- Network Security
- System Administration
- Data Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive configuration data and user credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline intrusion prevention systems (IPS) to detect and block exploitation attempts of known vulnerabilities.
- • Enforce zero trust segmentation to limit lateral movement within the network.
- • Deploy egress security and policy enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Utilize multicloud visibility and control solutions to detect and respond to command and control activities.
- • Regularly update and patch systems to remediate known vulnerabilities promptly.



