Threat Brief — 2026-08-15 — Three CVEs Hit CISA KEV, Router Botnet Emerges
Executive summary: CISA added three distinct high-severity CVEs to its Known Exploited Vulnerabilities catalog today — affecting Metabase, Microsoft Windows, and Cisco firewall products — all confirmed exploited in the wild. Separately, a new Mirai-derived botnet dubbed Evooo1Bot is actively compromising internet-facing routers and conscripting them into a SOCKS5 relay network. Patch and containment efforts should prioritise the KEV-listed vulnerabilities, especially the Cisco ASA/FTD flaw given its network-edge placement.
Top items
- CISA KEV: Metabase SQL Injection (CVE-2026-72898KEV) — Unauthenticated remote attackers can inject arbitrary SQL into the Metabase application database, potentially gaining administrator access. This is known exploited in the wild per CISA KEV. Organisations running Metabase should treat patching as urgent. This continues the KEV-exploitation story first reported 2026-07-30. (src: CISA:KEV)
- CISA KEV: Microsoft Windows AFD WinSock Use-After-Free (CVE-2026-68820KEV) — A use-after-free in the Windows Ancillary Function Driver for WinSock allows an authorised attacker to elevate privileges locally. Known exploited in the wild per CISA KEV. This is a privilege-escalation primitive likely chained with initial-access techniques; ensure Windows endpoints are current. Continues the KEV-exploitation story first reported 2026-07-30. (src: CISA:KEV)
- CISA KEV: Cisco ASA/FTD Heap Inspection (CVE-2026-20349KEV) — A heap inspection vulnerability in Cisco Secure Firewall ASA and FTD appliances. Known exploited in the wild per CISA KEV. Given these devices sit at the network perimeter, exploitation could enable traffic interception or further lateral movement. Continues the Cisco firewall exploitation story first reported 2026-07-30. (src: CISA:KEV)
- Evooo1Bot: New Mirai-based Linux botnet targeting routers — A modular Mirai variant called Evooo1Bot is actively compromising internet-facing gateway devices and converting them into SOCKS5 traffic relay nodes. The relay capability makes compromised routers valuable for proxying malicious traffic, obscuring attacker origins, and potentially facilitating credential stuffing or C2 channels. Network teams should audit exposed management interfaces on edge routers and check for unexpected SOCKS5 listeners. (src: BleepingComputer)
Themes
Edge-device targeting continues to accelerate. Both the Evooo1Bot botnet and the Cisco ASA/FTD KEV addition underscore that perimeter appliances — routers, firewalls, and gateways — remain prime targets. Attackers value these devices for their network position, persistent uptime, and often-lagging patch cycles. Prioritise exposure reduction on all internet-facing infrastructure this week.
