Metabase Zero-Day (CVSS 10.0) Exploited, Customer Data Stolen. A critical unauthenticated SQL injection zero-day in Metabase versions 1.58 and above has been actively exploited to steal customer data from companies including Framework and Tally. Attackers gain administrator access, harvest credentials, and exfiltrate data without any authentication, making patching self-hosted instances urgent.
Progress Kemp LoadMaster Hits CISA KEV After 792 Exploit Attempts. CVE-2026-8037, a command injection flaw in LoadMaster (CVSS critical), was added to CISA's Known Exploited Vulnerabilities catalog with a federal patch deadline of August 10, 2026. Attempts originated from 65 IP addresses across 18 countries, indicating broad opportunistic scanning.
CISA Flags TeamCity RCE CVE-2026-63077 Under Active Exploitation. The JetBrains TeamCity unauthenticated RCE flaw (CVSS 9.8) is being actively exploited in the wild, with federal agencies mandated to patch by August 8, 2026. On-premise installations are at risk; cloud-hosted instances are not affected. Learn more
New TONTOU and INTERRUPT INJECTION CPU Attacks Bypass Spectre v2 Mitigations. Two independently discovered microarchitectural attacks this week both defeat existing Spectre v2 defenses on Intel and AMD processors by re-poisoning the branch predictor after kernel mitigations have cleared it. Both can leak sensitive kernel memory including Linux password hashes from unprivileged local code. AMD has released a kernel patch; Intel does not consider a mitigation necessary.
18-Year-Old Linux SCTP Flaw Enables Root Access and Container Escape. CVE-2026-64564 (SCTPhantom), a use-after-free in Linux SCTP networking code present since 2008, allows local users to gain root on the host and escape containerized environments. Fixes have been backported to stable kernel versions and should be applied promptly in container-heavy environments.
Key Takeaway
Prioritize patching Metabase, Progress Kemp LoadMaster, and TeamCity immediately; review kernel update cadence for SCTP and Spectre v2 patches across all Linux hosts.
