The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.

Reports indicate that a zero-day vulnerability affecting the Metabase business-analytics platform is actively being exploited. This flaw, described as having maximum severity, permits remote attackers to gain administrator-level access. The lack of a Common Vulnerabilities and Exposures (CVE) identifier suggests it is a newly discovered or unpatched issue, potentially limiting the immediate availability of official advisories or patches.
The vulnerability is characterized as a SQL-related flaw, which typically implies an injection vulnerability. In such an attack, an adversary manipulates input fields to inject malicious SQL code directly into the application's database queries. If successful, this can bypass authentication, extract sensitive data, or even modify the database structure. Given the administrator-level access conferred by this specific zero-day, attackers could potentially gain full control over the Metabase instance.
Metabase, as a business-analytics platform, is designed to connect to various data sources within an organization, allowing users to query, visualize, and report on critical business data. The reported "wide blast radius" likely refers to the potential for compromise of these downstream data sources. An attacker with administrative access to Metabase could leverage its existing database connections to access or exfiltrate data from connected operational databases, data warehouses, or other data repositories.
Mitigation for SQL injection vulnerabilities typically involves robust input validation and parameterized queries, which separate user-supplied data from the SQL command itself. For an actively exploited zero-day without a CVE, immediate mitigation steps for affected organizations would generally include isolating Metabase instances from public networks, implementing strict network segmentation, and monitoring for unusual activity originating from or targeting the platform. Organizations should also prepare to apply patches as soon as they become available.
The potential impact extends beyond data exfiltration. With administrator access, an attacker could manipulate business intelligence reports, introduce false data, or disrupt critical analytical operations. Such actions could have significant operational and financial consequences for organizations relying on Metabase for data-driven decision-making.
This incident underscores the persistent threat posed by zero-day vulnerabilities, particularly in platforms that serve as central hubs for critical business data. The absence of a public CVE identifier often means that defenders are operating without specific guidance from vendors or security researchers, making proactive monitoring and robust incident response capabilities even more crucial. It highlights the ongoing challenge for organizations to secure complex application ecosystems against sophisticated and novel attack vectors.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.