LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Metabase

5 CVEs published in the last four months and 8 stories. Exploited flaws first.

Critical4
High1
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-72898exploited10criticalmetabaseMetabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endp26d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-5014810criticalmetabaseMetabase is an open-source business intelligence and embedded analytics tool.52d ago
CVE-2026-72898exploited10criticalmetabaseMetabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endp26d ago
CVE-2026-598279.9criticalmetabaseMetabase is an open-source business intelligence and embedded analytics tool.58d ago
CVE-2026-598269.1criticalmetabaseMetabase is an open-source business intelligence and embedded analytics tool.58d ago
CVE-2026-501477.6highmetabaseMetabase is an open-source business intelligence and embedded analytics tool.52d ago

Filter the full tracker by Metabase

Our coverage of Metabase

breach

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That ch

CVE-2026-20349

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software

CVE-2026-20349critical

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by specific deadlines. The vulnerabilities affect Cisco Secure Firewall, Microsoft Windows, and Metabase, with the Metabase flaw being a critical SQL injection that was actively exploited.

vulnerability

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.

breach

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses,

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

CVE-2023-38646critical

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has issued a critical alert regarding a zero-day vulnerability in its business intelligence software that has been actively exploited. The flaw allows unauthenticated attackers to inject SQL, leading to administrator access, credential theft, and data exfiltration. Metabase Cloud instances have been patched, and users of self-hosted versions are urged to update immediately.

breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]