Critical Metabase Flaw Under Active Attack: Update Now
A CVSS 10.0 SQL injection flaw in Metabase allows unauthenticated attackers to gain full admin access. CISA confirmed active exploitation on 11 August 2026. If you self-host Metabase, you need to update or mitigate today.
October 4, 2026
Security Updates & Threats