Forwarded Cybersecurity Information Advisory from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC) TWCERTCC-200-202608-00000013
【CVE-2026-20349】Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability (CVSS v3.1: 8.6)
【Ransomware Use: Unknown】 A heap inspection vulnerability exists in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). An unauthenticated, remote attacker could exploit this vulnerability to cause an unexpected reload of the device, resulting in a denial-of-service (DoS) condition.
【CVE-2026-68820】Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (CVSS v3.1: 7.0)
【Ransomware Use: Unknown】 A use-after-free vulnerability exists in the Microsoft Windows Ancillary Function Driver for WinSock. An authorized attacker could exploit this vulnerability to elevate privileges locally.
【CVE-2026-72898】Metabase SQL Injection Vulnerability (CVSS v3.1: 10.0)
【Ransomware Use: Unknown】 An SQL injection vulnerability exists in Metabase. An unauthenticated, remote attacker could exploit this vulnerability to inject arbitrary SQL commands into the Metabase application database, thereby gaining administrator privileges for the instance. Once privileges are obtained, the attacker may further modify application settings, steal stored credentials for connected databases, and read or export any data accessible through these connections.