Signal

Technology · 11 Aug

CISA confirms active exploitation of a Windows WinSock privilege-escalation flaw and adds it to the known-exploited catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 11 on evidence of active exploitation: CVE-2026-68820, a use-after-free in the Microsoft Windows Ancillary Function Driver for WinSock; CVE-2026-20349, a heap inspection vulnerability in Cisco Secure Firewall ASA and Firewall Threat Defense; and CVE-2026-72898, an SQL injection in Metabase.

A KEV listing is the agency's strongest signal to treat a flaw as urgent. Under Binding Operational Directive 26-04, federal civilian agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed systems that could grant full control of an asset, and must check whether attackers compromised systems before the patch was applied. CISA encourages every organization to apply the same risk-based priority, not just federally bound ones.

The catalog entry itself does not carry exploit or patch details — it is a signal to patch promptly against vendor guidance. The agency notes these vulnerabilities are a frequent attack vector and invites anyone aware of an exploited CVE not yet listed to nominate it.

Read the original at CISA →