DAILY BRIEFING
Metabase Zero-Day Exploited, N-able Issues Hotfix 2, Kemp LoadMaster Hits KEV
Today's briefing covers active zero-day exploitation in Metabase, critical hotfixes for N-able N-central, CISA KEV additions for Progress Kemp, and research into Atlassian Rovo and webmail CSS flaws.
5 stories2 min read

Enterprise software infrastructure faces heavy targeted activity today, with active exploitation reported across multiple administrative tools and management platforms. Unauthenticated attackers are actively exploiting a maximum-severity zero-day in self-hosted Metabase instances to gain full administrative privileges and extract stored database credentials.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase warned that an unauthenticated SQL injection zero-day flaw impacting versions x.58.0 and above was exploited in the wild. The vulnerability allows remote attackers to gain administrator access, modify configurations, and steal stored database credentials.
- Why it matters
- Self-hosted Metabase instances are exposed to full compromise, allowing unauthorized users to export sensitive business data and compromise underlying connected databases.
- What to do
- Apply the latest Metabase security patches immediately for all self-hosted deployments.
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog following active exploitation attempts. The critical command injection flaw in Progress Kemp LoadMaster allows unauthenticated remote attackers to execute arbitrary commands via unsanitized input endpoints.
- What to do
- Update Progress Kemp LoadMaster devices to the latest patched firmware version immediately.
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server.
- Why it matters
- Organizations using Atlassian Rovo risk leaking sensitive internal Jira and Confluence data if users open malicious links or files processed by the AI assistant.
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
PortSwigger research highlights CSS-based attack techniques across webmail services including Outlook, Gmail, Fastmail, and Yahoo Mail. Malicious CSS inside emails can escape message boundaries to capture passwords, hijack user interface actions, and exfiltrate third-party access tokens.
- Why it matters
- Webmail users face credential theft, account takeover, and token leakage when viewing untrusted HTML emails in vulnerable webmail interfaces.
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able released Hotfix 2 for N-central to counter active exploitation of CVE-2026-18577, an incomplete fix for CVE-2026-18556. Attackers exploited the flaw to gain unauthorized access and maintain persistence on managed systems.
Key takeaways
- Patch self-hosted Metabase instances immediately to protect against unauthenticated SQL injection and full administrative compromise.
- Apply N-able N-central Hotfix 2 to mitigate ongoing exploitation of CVE-2026-18577, even if Hotfix 1 was previously installed.