A CVSS 10.0 zero-day vulnerability in Metabase is being actively exploited in the wild, allowing attackers to obtain unauthenticated administrative access to corporate databases, according to an intelligence brief dated August 09, 2026. The brief lists analyst confidence at 100% and assigns a Critical threat level.
Metabase Zero-Day Details
The vulnerability in Metabase enables authentication bypass and full administrative access without valid credentials (listed as [CVE-TBD] in the brief) and is rated Critical (CVSS 10.0). The intelligence guidance marks Metabase as a P1 patch priority (≤24h) and recommends immediate patching to prevent unauthorized administrative access. The brief maps the activity to ATT&CK techniques including T1190 (Exploit Public-Facing Application) and T1078 (Valid Accounts).
Other Active Critical Threats
The report highlights multiple concurrent high-risk issues. N-able N-central RMM suffers a critical flaw actively exploited to compromise managed downstream systems and establish persistence; the vendor issued Hotfix 2 and the guidance marks it P1 (≤24h) with the vulnerability listed as [CVE-TBD]. Progress Kemp LoadMaster is reported with a command injection flaw leading to remote code execution and has been added to CISA KEV; it is also listed as Critical and P1 (≤24h) ([CVE-TBD]).
The Head Mare hacktivist group is reported to have compromised TrueConf servers to replace legitimate client installers with backdoored versions, constituting a software supply chain attack; TrueConf servers are assigned P2 patch priority (≤72h) and administrators are advised to update servers and verify installer integrity ([CVE-TBD]).
Atlassian’s Rovo AI is vulnerable to a prompt-injection technique dubbed “RovoBlast,” which can be used to trick the assistant into exfiltrating Jira, Confluence, and SharePoint data to external attacker-controlled servers; this issue is listed as High ([CVE-TBD]). The brief also describes newly discovered CSS injection techniques in webmail clients that can escape message boundaries and steal credentials. ATT&CK techniques cited include T1195.002 (Compromise Software Supply Chain), T1567 (Exfiltration Over Web Service), T1204.002 (User Execution: Malicious Link), and T1059 (Command and Scripting Interpreter).
IOC Feed and Mitigation Priorities
The live IOC feed and C2 blocklist cited in the brief show example IPs and associated malware: 162.243.103.246 (Emotet) on port 8080; 50.16.16.211 (QakBot) on port 443; 34.204.119.63 (QakBot) on port 443; 178.62.3.223 (QakBot) on port 443; and 27.133.154.218 (QakBot) on port 443. The brief notes a full IOC export available as a Google Sheet (two tabs: C2 IPs and OTX IOCs) with SHA256 hashes, IPs and domains, and that IOC sources include AbuseCH Feodo and AlienVault OTX.
Recommended actions in the brief are prioritized as follows:
1) [P1] Patch the Metabase zero-day vulnerability ([CVE-TBD]) immediately to prevent unauthorized administrative access.
2) [P1] Apply N-able N-central Hotfix 2 ([CVE-TBD]) immediately to block active exploitation and persistent access on managed systems.
3) [P1] Apply security patches for Progress Kemp LoadMaster ([CVE-TBD]) to mitigate active exploitation tracked in CISA KEV.
4) [P2] Update TrueConf Server ([CVE-TBD]) to the latest secure version and verify the integrity of client installers to prevent supply chain trojanization.
5) [P2] Implement strict input validation and boundary controls on webmail platforms (Outlook, Gmail, Proton Mail) to mitigate CSS injection attacks.
The brief concludes that organizations and managed service providers should prioritize the listed P1 patches within 24 hours and address P2 items within 72 hours to mitigate active exploitation and supply-chain risks.

