
CISA has added newly exploited vulnerabilities affecting Cisco Secure Firewall ASA/FTD and Microsoft Windows WinSock to its Known Exploited Vulnerabilities (KEV) Catalog.
The two vulnerabilities represent different attack scenarios:
- CVE-2026-20349 — Cisco Secure Firewall ASA/FTD vulnerability that can lead to denial of service.
- CVE-2026-68820 — Microsoft Windows
afd.sysuse-after-free vulnerability that can enable local privilege escalation.
Their addition to KEV is the key risk indicator. These are no longer vulnerabilities that organizations should evaluate solely on CVSS or theoretical exploitability. CISA has identified evidence of exploitation in the wild.
CVE-2026-20349 — Cisco Secure Firewall ASA and FTD
CVE-2026-20349 affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD).
The vulnerability is rated CVSS 8.6 and can result in a denial-of-service condition affecting the security appliance.
This is particularly significant because ASA and FTD devices frequently operate at the enterprise perimeter and may provide:
- Internet security controls
- Remote-access VPN
- Site-to-site VPN
- Network segmentation
- NAT
- Intrusion prevention
- Traffic inspection
A successful attack that causes a firewall to reload or become unavailable can therefore have consequences beyond simple availability loss.
An affected device could potentially cause:
Firewall disruption → VPN/service interruption → security-control degradation → operational impact
In environments with redundant firewalls, failover may reduce the immediate impact, but repeated exploitation could still create instability or operational disruption.
Cisco Assets That Require Immediate Review
Security teams should identify all deployments of:
- Cisco Secure Firewall ASA
- Cisco Secure Firewall FTD
- Internet-facing firewalls
- VPN termination devices
- HA firewall pairs
- Disaster-recovery firewalls
- Legacy or rarely used perimeter appliances
Version information should be correlated against Cisco’s affected and fixed releases.
Cisco provides security-advisory and software-checking resources to determine whether a particular deployment is vulnerable and which fixed release should be used.
The highest priority should be given to Internet-facing and VPN-facing devices.
CVE-2026-68820 — Microsoft Windows WinSock
CVE-2026-68820 affects the Windows Ancillary Function Driver for WinSock (afd.sys).
The vulnerability is a use-after-free flaw in a kernel-level Windows networking component and has a reported CVSS score of 7.0.
The risk is significantly higher than the CVSS score alone suggests because the vulnerability has been added to CISA KEV based on active exploitation.
Why afd.sys Is Important
afd.sys operates in the Windows networking stack.
A use-after-free vulnerability occurs when software continues to reference an object after that object’s memory has been released. Under exploitable conditions, this can result in memory corruption and potentially allow an attacker to execute code with elevated privileges.
The practical attack chain can look like:
Initial compromise
↓
User-level execution
↓
Exploitation of afd.sys
↓
Kernel-level privilege escalation
↓
SYSTEM-level access
This makes the vulnerability particularly valuable to attackers who already have a foothold on a Windows system but do not yet possess administrative privileges.
Why Local Privilege Escalation Matters
Local privilege escalation vulnerabilities are sometimes deprioritized because they normally require existing access to the system.
That approach is inappropriate when exploitation has already been observed.
An attacker who initially compromises a workstation through phishing, malware, stolen credentials or another vulnerability may begin with limited privileges.
A successful privilege-escalation exploit can then provide the ability to:
- Execute processes as SYSTEM
- Access protected resources
- Disable or tamper with security controls
- Harvest credentials
- Establish persistence
- Conduct further reconnaissance
- Move laterally
The vulnerability can therefore become an important second-stage component of an intrusion.
Windows Systems to Prioritize
Organizations should prioritize affected Windows systems according to both vulnerability exposure and business importance.
Particular attention should be given to:
- Privileged administrator workstations
- Domain controllers
- Jump servers
- Security-management systems
- Critical application servers
- Terminal servers
- High-value user endpoints
- Systems handling privileged credentials
Microsoft’s August 2026 security updates should be deployed according to the applicable supported Windows version.
Microsoft Security Update Guide
Immediate Actions for Security Teams
1. Identify Vulnerable Assets
Correlate CISA KEV entries with:
- CMDB
- Vulnerability scanners
- EDR platforms
- Network discovery
- Configuration-management databases
- Cloud and virtual infrastructure inventories
Do not rely on a single inventory source.
2. Prioritize Internet-Facing Cisco Devices
For CVE-2026-20349, identify vulnerable ASA/FTD devices that:
- Face the Internet
- Provide remote-access VPN
- Protect critical infrastructure
- Connect high-value environments
- Are exposed through externally accessible services
Upgrade them to the appropriate Cisco fixed release.
3. Deploy the August Windows Security Updates
Identify affected Windows systems and accelerate deployment of the applicable Microsoft security updates.
Privileged endpoints should receive particular attention because compromise of those systems can provide attackers with access to administrative credentials and sensitive infrastructure.
4. Hunt for Exploitation
Because both vulnerabilities have KEV status, remediation should be accompanied by retrospective analysis.
For Cisco infrastructure, examine:
- Unexpected firewall reloads
- Crash events
- Abnormal network traffic
- Configuration changes
- Unusual administrative activity
- VPN anomalies
For Windows systems, investigate:
- Unexpected privilege escalation
- Suspicious SYSTEM processes
- EDR alerts involving kernel components
- Security-control tampering
- Credential-access activity
- Suspicious activity preceding the patch installation
The objective is not simply to determine whether the system is patched.
It is to determine whether exploitation occurred before remediation.
KEV Should Drive Emergency Prioritization
A mature vulnerability-management program should treat KEV status as a major prioritization signal.
A practical decision model is:
Known exploitation + Internet exposure + Critical asset
= Emergency remediation
Whereas:
High CVSS + No known exploitation + Limited exposure
may still require remediation, but can normally be handled through the organization’s standard risk-based process.
This distinction is important for security teams managing thousands of vulnerabilities.
CISO Perspective
The latest KEV additions demonstrate two different forms of enterprise risk.
CVE-2026-20349 attacks the security boundary.
If a vulnerable firewall is disrupted, organizations can lose availability of critical perimeter and remote-access services.
CVE-2026-68820 attacks the endpoint privilege boundary.
An attacker who already has a foothold can potentially use the vulnerability to move from limited user privileges to SYSTEM-level control.
Both scenarios ultimately challenge the same security objective:
Maintain control of the attack surface before an attacker can turn vulnerability exposure into operational impact.
Final Takeaway
The addition of Cisco ASA/FTD and Windows WinSock vulnerabilities to CISA’s KEV Catalog should trigger an accelerated vulnerability-management response.
Security teams should:
- Identify affected Cisco and Windows assets.
- Prioritize Internet-facing and privileged systems.
- Deploy the appropriate Cisco and Microsoft fixes.
- Validate remediation.
- Hunt for evidence of prior exploitation.
- Report remaining exposure and exceptions to security leadership.
The central lesson is straightforward:
KEV status changes the remediation conversation from “How severe is this vulnerability?” to “How quickly can we eliminate our exposure?”
CISA Known Exploited Vulnerabilities Catalog



