Web_Logo
Remote Support
Security Alert: Windows Flaw Added to CISA Exploited List
Home » Security Alerts  »  Security Alert: Windows Flaw Added to CISA Exploited List

Security Alert: Windows Flaw Added to CISA Exploited List

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a Windows vulnerability, along with flaws in Cisco firewall and Metabase analytics software, to its list of vulnerabilities being actively exploited by attackers.

  • What it is: CVE-2026-68820 is a Windows driver flaw that lets an attacker who already has some foothold on a device take full control of it. Two related flaws affecting Cisco Secure Firewall and Metabase software were added to the same watch list.
  • Who is affected: Any business running Windows devices that are not fully patched, or using the named Cisco or Metabase products.
  • The risk: These flaws are not theoretical. They are already being used in real attacks, including a campaign using fake job offers to trick staff at targeted organisations, so unpatched systems are a live target.
  • What to do: Apply the latest Windows security updates without delay (see this month's Microsoft update for details), and confirm any Cisco firewall or Metabase software is on a current, patched version.

If your business is on OzComm's managed patching service, this update is already scheduled for your systems. If you manage patching yourself, we recommend actioning it this week.