www.cisa.gov 8/12/2026, 12:17:54 AM · external

CISA Logs CVE-2026-72898 Metabase Flaw in KEV Catalog

Developing story vulnerability 12 articles tracked
CISA adds Cisco firewall heap flaw CVE-2026-20349 to KEV catalog
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by CISA to help organizations manage vulnerabilities exploited in the wild. The catalog serves as a resource for vulnerability management and prioritization. The latest entry is CVE-2026-72898, a SQL Injection vulnerability in Metabase that allows unauthenticated attackers to gain admin access, posing risks of data theft and manipulation.

Organizations are urged to follow mitigations per vendor instructions and comply with CISA's applicable security directives. The catalog is accessible in various formats, including CSV and JSON. Users can also subscribe for updates on the catalog.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline