Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect, described ...
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing ...
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
Researchers found that a crafted link could inject malicious instructions into Atlassian Rovo and potentially turn its broad enterprise access and autonomous agents into a data-exfiltration tool.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
6don MSN
This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers
Huntress spotted a white whale - a malicious toolkit stored as a database object.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results