Metabase says its critical zero-day was actively exploited
An unauthenticated SQL-injection path can lead to Metabase administrator access, exposed database credentials, and data theft.
4 of 4 advisories
CISA reports that unsafe deserialization in the TeamCity agent polling protocol can permit unauthenticated remote code execution.
CISA says default Langflow deployments may permit unauthenticated attackers to achieve full remote code execution.
| Published | Advisory | Technology | Signal | Priority |
|---|---|---|---|---|
Metabase MetabaseGHSA-vwf4-m7j8-wcjf | Analytics, Data platforms | Active exploitation | Act now | |
JetBrains TeamCityCVE-2026-63077 | CI/CD, Developer infrastructure | Known exploited | Act now | |
IBM LangflowCVE-2026-9198 | AI, Agent workflows | Known exploited | Act now | |
Progress LoadMasterCVE-2026-8037 | Infrastructure, Load balancers | Known exploited | Act now |
Either the filters are too specific, or security has finally been solved. Probably the filters.