The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog to include several newly discovered flaws, including a heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD), identified as CVE-2026-20349 with a CVSS score of 8.6. Additionally, a vulnerability in Microsoft Windows Ancillary Function Driver for WinSock, designated as CVE-2026-68820 with a CVSS score of 7.0, has been added to the catalog. A Metabase flaw has also been included, highlighting the ongoing efforts to identify and address potential security risks. The exploitation status of these vulnerabilities, particularly CVE-2026-20349, is being closely monitored by CISA1. This matters to cybersecurity practitioners because the addition of these vulnerabilities to the KEV catalog indicates a potential imminent threat, requiring prompt attention and patching to prevent exploitation.