Metabase SQL Injection Zero-Day Exploited in Data-Theft Attacks
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
Category
55 published analyses.
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
Cisco released patches for 12 critical vulnerabilities in Catalyst SD-WAN and IOS XE software impacting devices in all configurations.
High-severity vulnerabilities in ABB Ability Zenon IIoT services using MongoDB 4.2 allow unauthorized access, denial of service, and potential data compromise.
HashiCorp, Veeam, and the Django Software Foundation released patches for 11 vulnerabilities, including a critical CVSS 10.0 cross-tenant bug affecting Terraform MCP Server, Veeam Service Provider Console, and Django software.
A critical vulnerability in cPanel (CVE-2026-58048) allowed authenticated hosting customers to execute SQL commands with root database privileges, risking full database control.
A high-severity vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers allows modification of DNA data output files, risking inaccurate test results in healthcare settings.
CISA added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog due to active exploitation, prioritizing federal agency remediation under BOD 26-04.
A firmware vulnerability in Coldcard hardware wallets enabled attackers to steal approximately $70 million in Bitcoin by draining over 1,000 addresses in under an hour.
Adobe Campaign Classic includes a critical CVSS 10.0 vulnerability (CVE-2026-48449) that allows arbitrary code execution without user interaction.
A critical vulnerability in Azure Cosmos DB enabled attackers to escape the Gremlin query sandbox and gain full read/write access to multiple customer databases.
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote code execution, posing significant risk to enterprise environments.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary server files through malicious image uploads, risking exposure of sensitive data.
A critical vulnerability in the Ruflo open-source agent platform allows unauthenticated remote code execution and poisoning of AI memory, posing significant risks to AI model operations.
Broadcom published updates for critical VMware vulnerabilities in ESX, vCenter, Workstation, and Fusion enabling authentication bypass and VM escape with high severity.
Arista released a patch for a critical command injection zero-day vulnerability currently exploited in on-premises VeloCloud Orchestrator deployments, affecting enterprise network management.
A critical stack buffer overflow in OpenSSL affects Siemens Desigo CC versions V7, V8, and V9 before 9.0.1, posing risks of remote code execution or denial of service.
A critical DHCPv6 stack overflow vulnerability in OpenWrt's default network service odhcpd allows unauthenticated remote root code execution.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
A critical pre-authentication remote code execution vulnerability in vBulletin forum software has been patched following the public release of an exploit, enabling unauthenticated attackers to execute arbitrary PHP code.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
The Certighost exploit enables low-privileged Active Directory users to obtain Domain Controller certificates and authenticate as domain controllers, risking critical Kerberos credential compromise.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
Multiple high-severity vulnerabilities in Weintek cMT3092X HMI may allow attackers to escalate privileges and steal credentials, impacting critical manufacturing environments.
CISA has added CVE-2026-16232 and CVE-2026-50522 to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation targeting Check Point SmartConsole and Microsoft SharePoint.
CISA has mandated U.S. federal agencies to urgently address a remote code execution vulnerability actively exploited in Langflow, posing critical risks to infrastructure security.
A critical authentication bypass vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows unauthenticated attackers full administrative control, risking critical infrastructure disruptions.
Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, now actively exploited after a public proof-of-concept was released, enabling remote code execution via deserialization of untrusted data.
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.
F5 released patches for CVE-2026-42533, a critical nginx flaw allowing remote, unauthenticated attackers to trigger a heap buffer overflow that can crash workers or enable remote code execution.
A zero-day vulnerability named LegacyHive enables privilege escalation on fully updated Windows systems, allowing attackers to gain admin-level access.
CISA has directed federal agencies to urgently patch two actively exploited vulnerabilities in Fortinet FortiSandbox, highlighting critical risks to government and enterprise environments.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.
SonicWall disclosed two critical zero-day vulnerabilities in SMA1000 devices being exploited in active attacks, highlighting urgent risk to enterprise network security.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Progress Software advises ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat, disabling account access as a precaution.
OpenPLC v3 contains a critical authenticated arbitrary file write vulnerability that can lead to native code execution through compiling malicious files. This affects critical infrastructure sectors worldwide and requires urgent mitigation.
Researchers tested 281 popular free Android VPN apps and discovered many leak user traffic, transmit unencrypted data, and include tracking. These apps, collectively installed over 2.4 billion times, fail to meet basic privacy and security standards.
Ubiquiti released updates to fix critical vulnerabilities in UniFi Connect, Talk, Access, Protect, and OS. These flaws could allow privilege escalation and arbitrary command execution.
Threat actors are actively attempting to exploit a critical vulnerability in Gitea Docker images less than two weeks after it was patched. The flaw allows unauthenticated clients to escalate privileges by abusing the 'X-WEBAUTH-USER' header.
A critical use-after-free flaw in Linux's KVM hypervisor allows guest VMs on Intel and AMD systems to corrupt host kernel memory, potentially escaping the virtual environment. The vulnerability, known as Januscape (CVE-2026-53359), includes a public PoC that crashes hosts with a more impactful exploit reportedly in development.
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is now being actively exploited in cyberattacks, according to KEVIntel. This flaw demands immediate attention due to its maximum severity rating.
A new Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows unprivileged users to escalate to root, impacting Linux desktops, servers, and Android devices. A patch has already been released.
Security firm runZero disclosed seven vulnerabilities in FatFs, a widely used filesystem library in embedded devices including security cameras and drones. These flaws pose a risk due to FatFs's ubiquity in consumer and industrial firmware.
Attackers have started exploiting a critical CVE-2026-46817 vulnerability in the Oracle E-Business Suite financial application, as reported by Defused. This flaw poses significant risk to enterprises using Oracle EBS.
Hackers are actively exploiting a critical vulnerability in SimpleHelp (CVE-2026-48558) to distribute Djinn Stealer, a new cross-platform information stealer targeting Windows, macOS, and Linux. This campaign represents a novel threat leveraging an undocumented malware strain.
CISA has set a Sunday deadline for federal agencies to patch a critical vulnerability in Cisco Unified Communications Manager Server actively exploited in attacks. Immediate action is urged to prevent further compromise.
CISA has issued a warning about an actively exploited critical code injection vulnerability, CVE-2025-67038, affecting Lantronix EDS5000 Series devices. Federal agencies are urged to apply patches by June 26, 2026, to prevent potential remote code execution.
CISA has issued a warning about hackers actively exploiting severe vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. These flaws carry a maximum severity rating and pose significant risk to affected organizations.
Mandiant has exposed how attackers exploited a zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN to create rogue root accounts on devices, raising serious security concerns. This vulnerability enables full control of targeted network appliances, potentially impacting enterprise operations.
A high-severity Server-Side Request Forgery vulnerability in Cisco Unified Communications Manager Server, tracked as CVE-2026-20230, is actively being exploited in the wild. Security teams should prioritize detection and mitigation to prevent potential compromise.