As cited
Copy frozen at (site build).
vulnerabilities
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical SQL injection vulnerability in Metabase was actively exploited in zero-day attacks to breach customer instances and steal data, with confirmed impacts to Framework and Tally. The vulnerability allowed attackers to compromise Metabase deployments before patches were available.
Why it matters: Organizations running Metabase need to immediately patch or isolate their instances; this zero-day is under active exploitation with confirmed customer breaches already occurring.
- Source published
- First seen by Cybersecurity Tracker