1. Top Action Item

Patch Metabase immediately. A maximum-severity vulnerability (CVSS 10.0, no CVE assigned) is being exploited in the wild as a zero-day, letting unauthenticated attackers inject arbitrary SQL into the Metabase application database and gain admin access. Upgrade any internet-facing Metabase instance to the vendor's patched release now, then audit for rogue admin accounts. Also apply N-able N-central Hotfix 2 and the Progress Kemp LoadMaster patch (CVE-2026-8037) this week — both are under active attack.


2. Exploited This Week

Metabase (no CVE identifier)

Progress Kemp LoadMaster — CVE-2026-8037

N-able N-central (CVE: see source)


3. Critical Patch Roundup

WordPress core — CVE-2026-64638

Linux kernel SCTP use-after-free (CVE: see source)

Atlassian Rovo (CVE: see source)

Microsoft-published advisories (MSRC)


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Metabase — vendor patched release (no CVE; CVSS 10.0) — exploited in the wild / unauthenticated admin access.
  2. Progress Kemp LoadMaster — CVE-2026-8037 (CVSS 9.6) — exploited in the wild / CISA KEV.
  3. N-able N-central — Hotfix 2 (CVE: see source) — exploited / attackers persisting on managed systems.
  4. Linux stable kernels 7.1.6 / 6.18.42 / 6.12.101 / 6.6.148 (CVE: see source) — local root + container escape via SCTP.
  5. WordPress core — CVE-2026-64638 (CVSS 8.9) — pre-auth XSS → PHP code execution; all versions affected.
  6. Atlassian Rovo — see source — Jira/Confluence data exfiltration via prompt injection.
  7. open-iscsi — CVE-2026-44944 / CVE-2026-44943 — control-socket auth bypass and root file-write (see source).
  8. Docker Compose — CVE-2025-62725 — path traversal via OCI artifact layer annotations (see source).
  9. QEMU guest agent — CVE-2026-12080 — local privilege escalation via symlink attack (see source).
  10. PyJWT — CVE-2026-32597 / CVE-2026-48524 — JWT crit header violation and JWKS endpoint DoS (see source).

Sources