Organizations should apply vendor-provided patches immediately. For Cisco ASA/FTD, consult Cisco security advisories. For Microsoft Windows, apply the latest security updates. For Metabase, follow the vendor's guidance. Additionally, review systems for indicators of compromise before patching, as recommended by BOD 26-04.
Quick answers
What is CVE-2026-68820?
Organizations should apply vendor-provided patches immediately. For Cisco ASA/FTD, consult Cisco security advisories. For Microsoft Windows, apply the latest security updates. For Metabase, follow the vendor's guidance. Additionally, review systems for indicators of compromise before patching, as recommended by BOD 26-04.
How severe is CVE-2026-68820?
high
Is CVE-2026-68820 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-68820 be mitigated?
Organizations should apply vendor-provided patches immediately. For Cisco ASA/FTD, consult Cisco security advisories. For Microsoft Windows, apply the latest security updates. For Metabase, follow the vendor's guidance. Additionally, review systems for indicators of compromise before patching, as recommended by BOD 26-04.
CVSS
—
Vendor
Cisco
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Cisco Secure Firewall Adaptive Security Appliance (ASA), Cisco Firewall Threat Defense (FTD), Microsoft Windows Ancillary Function Driver for WinSock, Metabase
Mitigation
Organizations should apply vendor-provided patches immediately. For Cisco ASA/FTD, consult Cisco security advisories. For Microsoft Windows, apply the latest security updates. For Metabase, follow the vendor's guidance. Additionally, review systems for indicators of compromise before patching, as recommended by BOD 26-04.
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-20349 (Cisco Secure Firewall ASA/FTD heap inspection), CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock use-after-free), and CVE-2026-72898 (Metabase SQL injection). Federal agencies are required to prioritize patching these flaws under BOD 26-04, and all organizations are urged to adopt risk-based vulnerability management.