<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Metabase Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Metabase.</description><lastBuildDate>Sat, 12 Sep 2026 21:30:25 GMT</lastBuildDate><item><title>CISA Adds Three Known Exploited Vulnerabilities to Catalog</title><link>https://cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog</link><guid isPermaLink="false">cst-4260</guid><description>CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: a Cisco firewall heap inspection flaw, a Microsoft Windows use-after-free issue, and a Metabase SQL injection bug. The agency reinforced that federal agencies must prioritize patching KEV-listed vulnerabilities on publicly exposed systems and investigate potential compromise before patch application, per Binding Operational Directive 26-04. CISA encourages all organizations to adopt risk-based vulnerability management aligned with KEV prioritization. Grouped because: title similarity 56 plus shared entities: CVE-2026-20349 Sources: CISA Alerts and Advisories, Cisco Talos, The Hacker News, Help Net Security.</description><pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate></item></channel></rss>