Government Advisory

Three Actively Exploited Vulnerabilities Added to CISA's Critical List — Cisco, Microsoft and Metabase Affected

CISA · 11 Aug 2026
Key Takeaway If your business uses Cisco ASA/FTD firewalls, Windows systems, or Metabase, check for and apply security patches immediately, as these vulnerabilities are already being exploited in the wild.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The affected products are Cisco's Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD), Microsoft Windows' Ancillary Function Driver for WinSock, and the popular open-source analytics tool Metabase, which has a SQL injection flaw.

While the KEV Catalog is primarily used to direct US federal agencies on which vulnerabilities to fix urgently, it serves as a valuable early-warning signal for businesses everywhere. These flaws are being actively used in real-world attacks, meaning cybercriminals already have working methods to exploit them — making delayed patching particularly risky.

Australian small businesses using Cisco firewall products, Windows systems, or Metabase for business intelligence and reporting should check whether they are running affected versions and apply available security updates without delay. Even if your business isn't a direct government target, attackers often use automated scanning tools to find and exploit unpatched systems wherever they exist.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.