securityonline.info 8/17/2026, 2:40:50 AM · external

Critical Metabase SQLi flaw lets attackers seize full admin control

Critical Metabase SQLi flaw lets attackers seize full admin control
Developing story vulnerability 20 articles tracked
Critical Metabase SQLi flaw lets attackers seize full admin control
CyberSIXT Evidence Panel

THE weekly threat intelligence report for mid-August 2026 highlights the discovery of 3,976 new vulnerabilities, emphasizing the need for immediate patching to protect enterprise systems. Key vulnerabilities include a critical SQL injection in Metabase (CVE-2026-72898) allowing full administrative access, a denial-of-service flaw in Cisco appliances (CVE-2026-20349), and a privilege escalation flaw in the Windows WinSock driver (CVE-2026-68820).

Moreover, cloud risks were noted, such as authorization flaws in Microsoft Teams and Azure SQL Database. Organizations are urged to patch identified vulnerabilities swiftly and continuously monitor systems to mitigate risks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline