The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline last week after detecting "unusual activity on ...
Tech Times on MSN
Metabase SQL Injection Breached Five Companies, Exposed All Connected Database Credentials
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.
A critical-severity SQL injection vulnerability in Metabase has been exploited as a zero-day to gain administrative privileges.
A critical Gremlin API vulnerability exposed a path to any Cosmos DB instance, including Microsoft’s own services, before the company redesigned the platform.
Centauri Systems launches Launchpad, a fully managed developer portal for Apigee X, now available on Google Cloud ...
For the third year in a row, prompt injection tops the OWASP GenAI / LLM Top Ten list issued today as being the most ...
By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.
LLMs became reliably good at writing SQL only six or nine months ago. Soon agents will handle boring data tasks, but ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results