Metabase critical SQL injection flaw actively exploited (CVE-2026-72898)
Vulnerability
Summary
Hide ▲
Show ▼
Metabase CVE-2026-72898 is a critical SQL injection flaw that was exploited as a zero-day, creating immediate risk for exposed Metabase deployments. The flaw was linked to a breach affecting ShipMonk systems and downstream customer data exposure. Any organization storing sensitive records in Metabase should treat the vulnerability as high priority.
Related Happenings
ShipMonk hit by network compromise
Incident
H score43
First: 13.08.2026 18:13
Last: 13.08.2026 18:13
Sources 1
How related:
ShipMonk informed the hardware wallet maker of a breach on August 10, 2026, following unauthorized access to their systems.
About this happening:
ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider bre...
ShipMonk hit by network compromise
IncidentHow related: ShipMonk informed the hardware wallet maker of a breach on August 10, 2026, following unauthorized access to their systems.
About this happening: ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider bre...
CISA orders FCEB patching for CVE-2026-9082
Public Sector Action
H score70
First: 26.05.2026 11:46
Last: 26.05.2026 11:46
Sources 1
About this happening:
CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...
CISA orders FCEB patching for CVE-2026-9082
Public Sector ActionAbout this happening: CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...
Initial-access handoff time drops to 22 seconds across Mandiant investigations
Trend
H score26
First: 23.03.2026 17:00
Last: 23.03.2026 17:00
Sources 1
About this happening:
Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...
Initial-access handoff time drops to 22 seconds across Mandiant investigations
TrendAbout this happening: Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
05.09.2026 17:17 2 articles · 2h ago
Zero-day Metabase exploitation compromises ShipMonk systems
Exploitation ObservedShipMonk systems were compromised through zero-day exploitation of CVE-2026-72898 in Metabase, exposing customer order details stored in a Metabase instance used by ShipMonk for Trezor.
Show sources
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted — thehackernews.com — 05.09.2026 17:17
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted — thehackernews.com — 05.09.2026 17:17
-
05.09.2026 17:17 1 articles · 2h ago
Trezor discloses 67,000 U.S. customers' data exposed in ShipMonk breach
Initial DisclosureTrezor disclosed that a ShipMonk breach exposed names, email addresses, phone numbers, shipping addresses, and order numbers for 67,000 U.S. customers, adding to 13,689 customers it had disclosed the previous month.
Show sources
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted — thehackernews.com — 05.09.2026 17:17