View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Metabase SQL Injection Zero-Day Exploited to Breach Customer Instances

๐Ÿšจ ACTIVE EXPLOITATION

  • Metabase SQL Injection Zero-Day Exploited to Breach Customer Instances Attackers exploited a critical Metabase SQL injection zero-day in customer instances.

    • Metabase Cloud and self-hosted deployments in versions 0.58 through 0.63 were affected; Cloud instances were patched by Metabase.
    • The critical unauthenticated SQL injection flaw has a CVSS score of 10.0 and no CVE identifier.
    • Exploitation could grant administrator access, expose connected database credentials, and enable data theft.
    • Attacks used POST /api/session/reset_password returning 400, followed by GET /api/user/current returning 200.
    • Fixed releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. ๐Ÿ“„ Source: metabase.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • CISA Adds Progress Kemp LoadMaster Flaw to KEV After 792 Exploit Attempts Attackers are actively exploiting a critical command injection flaw in Progress Kemp LoadMaster.

    • Progress Kemp LoadMaster deployments are affected, including organizations using the application delivery controller.
    • CVE-2026-8037 carries a CVSS score of 9.6 and enables arbitrary command execution.
    • Attackers send specially crafted requests to vulnerable LoadMaster instances.
    • CISA added the flaw to its Known Exploited Vulnerabilities catalog after 792 reported exploit attempts. ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Attackers Exploit N-able N-central Authentication Bypass to Reach Managed Systems Attackers exploited an N-central authentication bypass to access managed systems.

    • The issue affects MSPs using N-able N-central in on-premises and cloud-hosted deployments.
    • CVE-2026-18577 is an authentication-bypass flaw affecting N-central versions before 2026.3.1.7.
    • Attackers bypassed the fix for CVE-2026-18556 to gain administrative access to N-central servers.
    • They abused the Take Control feature to reach managed endpoints and installed Cloudflare tunnel services for persistence.
    • Reported IOCs include 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, and 68.235.46.214. ๐Ÿ“„ Source: n-able.com ยท ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-14526 โ€” CVSS 9.8 โ€” AI Copilot โ€“ Content Generator through 1.5.6 - Unauthenticated Privilege Escalatio...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check