A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability ...
Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect, described ...