daily cyber × ai intelligence

index

tagged

[CVE-2026-72898]

2 editions · 2 items

August 31, 2026

  • A working PoC for a Metabase SQL injection (CVE-2026-72898) is being advertised on a cybercrime forum, with the seller claiming full database extraction, mass scanning and escalation to RCE, plus 600+ compromised databases and 50+ RCE sessions already in hand (DailyDarkWeb). The claims are unverified, but internet-facing Metabase deployments deserve an immediate version check. · Vulnerabilities & Exploits

in Fully Patched, Still Domain Admin

August 14, 2026

  • The Metabase pre-auth SQL injection zero-day now has a CVE and a technical writeup. Horizon3 details CVE-2026-72898, an actively exploited unauthenticated SQLi in Metabase before x.63.5 that yields admin access, config modification, and data theft — the flaw that had circulated without a CVE now formally tracked (earlier coverage). (Horizon3) · Vulnerabilities & Exploits

in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries