CISA's list that day
11 August 2026
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD), Microsoft Windows Ancillary Function Driver for WinSock and Metabase. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-72898SQL Injection | Metabase Metabase | Patch nowForensic triage required by CISA | 0.19 | ||
| CVE-2026-20349Heap Inspection | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Patch soon | 0.01 | ||
| CVE-2026-68820Use-After-Free | Microsoft Windows Ancillary Function Driver for WinSock | Patch soon | 0.00 |