Today’s Field Note

Three actively exploited flaws are worth your morning, and none of them care about your patch window. Metabase is bleeding: a maximum-severity, unauthenticated SQL injection zero-day (CVSS 10.0, no CVE assigned yet) is being used in the wild to breach instances and steal data, with Framework and Tally already named as victims. CISA added Progress Kemp LoadMaster’s CVE-2026-8037 (CVSS 9.6, command injection) to KEV after roughly 792 recorded exploit attempts, so this is spray-and-pray, not theory. And N-able shipped N-central Hotfix 2 precisely because attackers are already inside managed systems and adapting faster than the first round of fixes. RMM compromise means downstream customers, so treat N-central like it is on fire until proven otherwise.

Today’s Action

  • Apply the emergency Metabase update immediately, or pull the instance off the internet if you cannot patch today. Hunt for anomalous SQL and outbound data transfers going back several weeks.
  • Patch Progress Kemp LoadMaster against CVE-2026-8037 now. If exposed to the internet, review logs for command injection attempts and unexpected admin activity.
  • Deploy N-able N-central Hotfix 2 and assume compromise: audit for new accounts, rogue scheduled tasks, and persistence on both the N-central server and managed endpoints.
  • For all three, rotate credentials and API tokens that touched the affected systems. SQLi and RMM access both mean stolen secrets.
  • Check whether you are downstream of Framework, Tally, or an MSP running N-central, and start the customer-notification conversation before it starts itself.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

The patch window closed while you were reading the changelog.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.