π‘οΈ Cybersecurity Vulnerability Watch
Patch Metabase immediately. A maximum-severity vulnerability (CVSS 10.0, no CVE assigned) is being exploited in the wild as a zero-day, letting unauthenticated attackers inject arbitrary SQL into theβ¦
π‘οΈ Cybersecurity Vulnerability Watch
Week of: 2026-08-02 to 2026-08-08 Reporting window: Most recently completed SundayβSaturday (excludes the in-progress week).
1. Top Action Item
Patch Metabase immediately. A maximum-severity vulnerability (CVSS 10.0, no CVE assigned) is being exploited in the wild as a zero-day, letting unauthenticated attackers inject arbitrary SQL into the Metabase application database and gain admin access. Upgrade any internet-facing Metabase instance to the vendor's patched release now, then audit for rogue admin accounts. Also apply N-able N-central Hotfix 2 and the Progress Kemp LoadMaster patch (CVE-2026-8037) this week β both are under active attack.
2. Exploited This Week
Metabase (no CVE identifier)
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 10.0)
- What's happening: Actively exploited in the wild as a zero-day; unauthenticated remote attackers inject arbitrary SQL into the Metabase application database to gain admin access.
- Fix: Apply the patched Metabase release per the vendor's advisory (see source for exact version).
Progress Kemp LoadMaster β CVE-2026-8037
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 9.6)
- What's happening: Command injection flaw added to CISA's Known Exploited Vulnerabilities catalog after 792 reported exploit attempts; can be weaponized for arbitrary command execution.
- Fix: Apply the vendor's patch for CVE-2026-8037 (see source for version).
N-able N-central (CVE: see source)
- Source: The Hacker News
- Link: The Hacker News
- Severity: see source
- What's happening: Ongoing exploitation of a recently disclosed flaw in the Remote Monitoring and Management product; attackers have reached managed systems and are persisting.
- Fix: Install N-able N-central Hotfix 2 (in addition to earlier hotfixes) β see source.
3. Critical Patch Roundup
WordPress core β CVE-2026-64638
- Source: The Hacker News
- Link: The Hacker News
- Severity: High (CVSS 8.9)
- What's happening: Pre-authentication reflected XSS in the WordPress login screen affects every version and can be chained into PHP code execution when a logged-in administrator interacts with an attacker-controlled page.
- Fix: Update WordPress to the fixed release (see source for version).
Linux kernel SCTP use-after-free (CVE: see source)
- Source: The Hacker News
- Link: The Hacker News
- Severity: see source (researchers demonstrated full root on host and container escape)
- What's happening: 18-year-old use-after-free in Linux SCTP networking code, exploitable by local users to gain root and escape containers.
- Fix: Update to stable kernels 7.1.6, 6.18.42, 6.12.101, or 6.6.148 (released August 3).
Atlassian Rovo (CVE: see source)
- Source: The Hacker News
- Link: The Hacker News
- Severity: see source
- What's happening: Attacker-controlled instructions hidden in content Rovo reads can exfiltrate Jira/Confluence data to an outside server; two research teams found it independently, and only one route is confirmed closed.
- Fix: See source β follow Atlassian's guidance; one attack route remains unconfirmed as fixed.
Microsoft-published advisories (MSRC)
- Source: Microsoft MSRC
- Link: CVE-2026-44944 Β· CVE-2026-44943 Β· CVE-2026-32597 Β· CVE-2026-48524 Β· CVE-2025-62725 Β· CVE-2026-12080 Β· CVE-2026-68480
- Severity: see source for each
- What's happening / Fix:
- CVE-2026-44944 β open-iscsi iscsiuio control-socket authentication bypass. Fix: see source.
- CVE-2026-44943 β open-iscsi remote limited file-write as root via discovery. Fix: see source.
- CVE-2026-32597 β PyJWT accepts unknown
critheader extensions (RFC 7515 MUST violation). Fix: see source. - CVE-2026-48524 β PyJWT PyJWKClient allows unbounded JWKS endpoint requests via attacker-controlled
kidvalues (DoS). Fix: see source. - CVE-2025-62725 β Docker Compose path traversal via OCI artifact layer annotations. Fix: see source.
- CVE-2026-12080 β QEMU guest agent local privilege escalation via symlink attack in guest-ssh-add-authorized-keys. Fix: see source.
- CVE-2026-68480 β x86 Safe-RET robustness against interrupt injection. Fix: see source.
4. Home / SOHO Impact
- Update WordPress now β CVE-2026-64638 affects every version; a pre-auth XSS on the login screen can escalate to PHP code execution, so blog and small-business sites should patch as soon as the fix is installed.
- macOS users, watch for fake verification pages β ClickFix-style attacks are delivering a stealer that can drain crypto wallets, browser passwords, and Apple iCloud Keychain data. Never paste terminal commands from a webpage.
- Be cautious with webmail content β new research shows CSS inside an email can escape the message boundary and interfere with the interface in Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, potentially capturing passwords and tokens.
- Check your home router for firmware updates β researchers flagged 15 TP-Link bugs related to zero-trust provisioning; keep router firmware current.
- Linux home servers and NAS boxes β if you use SCTP, update to the fixed stable kernels (7.1.6, 6.18.42, 6.12.101, 6.6.148) to close a local-root and container-escape flaw.
5. Enterprise Impact
- Metabase: upgrade internet-facing instances immediately (CVSS 10.0, exploited as a zero-day); audit the application database and admin accounts for signs of compromise.
- Progress Kemp LoadMaster (CVE-2026-8037): patch now β CISA KEV entry with 792 reported exploit attempts; inspect appliance logs for command-injection / post-exploitation activity.
- N-able N-central: deploy Hotfix 2; because attackers reached managed systems and are persisting, audit managed endpoints and RMM credentials for unauthorized access.
- Linux hosts: update to the fixed stable kernels if SCTP is reachable by untrusted local users β researchers demonstrated host root and container escape.
- Atlassian Rovo: limit what the AI assistant can read in Jira/Confluence and follow Atlassian's guidance; one data-exfiltration route remains unconfirmed as fixed.
- npm supply chain: nearly 800 malicious packages deliver a cross-platform RAT/infostealer, and the ChainDrop worm extracts GitHub Actions runner secrets β audit lockfiles, review CI/CD secrets, and look for typo-squatted or "AI slop" dependency names.
- Vishing (UNC6671): attackers posing as IT help desk staff are calling employees' personal phones to steal SaaS data, targeting financial services, private equity, and professional services β verify "urgent security migration" calls through a second channel.
- AI token jacking: stolen developer API keys are being used to hijack AI tokens and resources β review how AI API keys are stored and monitor for anomalous usage.
6. What To Patch First
- Metabase β vendor patched release (no CVE; CVSS 10.0) β exploited in the wild / unauthenticated admin access.
- Progress Kemp LoadMaster β CVE-2026-8037 (CVSS 9.6) β exploited in the wild / CISA KEV.
- N-able N-central β Hotfix 2 (CVE: see source) β exploited / attackers persisting on managed systems.
- Linux stable kernels 7.1.6 / 6.18.42 / 6.12.101 / 6.6.148 (CVE: see source) β local root + container escape via SCTP.
- WordPress core β CVE-2026-64638 (CVSS 8.9) β pre-auth XSS β PHP code execution; all versions affected.
- Atlassian Rovo β see source β Jira/Confluence data exfiltration via prompt injection.
- open-iscsi β CVE-2026-44944 / CVE-2026-44943 β control-socket auth bypass and root file-write (see source).
- Docker Compose β CVE-2025-62725 β path traversal via OCI artifact layer annotations (see source).
- QEMU guest agent β CVE-2026-12080 β local privilege escalation via symlink attack (see source).
- PyJWT β CVE-2026-32597 / CVE-2026-48524 β JWT
critheader violation and JWKS endpoint DoS (see source).
Sources
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication β https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts β https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist β https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP β https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers β https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers β https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens β https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html
- Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer β https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets β https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data β https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html
- ChainDrop: Inside a Self-Propagating npm Worm β https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
- Token Jacking: Cybercriminals Could Be Stealing Your AI Resources β https://unit42.paloaltonetworks.com/ai-token-jacking/
- 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning β https://www.darkreading.com/endpoint-security/15-tp-link-bugs-risks-zero-trust-provisioning
- CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44944
- CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44943
- CVE-2026-32597 PyJWT accepts unknown
critheader extensions (RFC 7515 Β§4.1.11 MUST violation) β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32597 - CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48524
- CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62725
- CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-12080
- CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68480
More from News