24-Hour Security Roundup: Vulnerabilities, 0-Days, CVEs, and Hardware Flaws (2026-08-11)
A roundup of significant software and hardware security issues from the past 24 hours, compiled from public, web-verified sources.
Key points
Metabase critical SQL injection 0-day (CVSS 10.0)
- Identifier: GHSA-vwf4-m7j8-wcjf (no CVE assigned as of 2026-08-10).
- Affected versions: v0.58–v0.63 (OSS) and v1.58–v1.63 (Enterprise/Pro); risk concentrated in self-hosted deployments.
- Unauthenticated attackers inject SQL via
/api/session/reset_password, escalate to admin, steal database credentials, exfiltrate data, and alter configuration. - Active exploitation confirmed: Framework and Tally leaked customer names, emails, phone numbers, addresses, and login IPs (payment/order data unaffected). Metabase Cloud was attacked but automatically patched; thousands of exposed self-hosted instances estimated.
- Fixed versions: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5.
- Attack signature: a POST to
/api/session/reset_passwordreturning 400, followed by a successful GET/api/user/current(200). Mitigation: block the endpoint, rotate credentials, review logs. - Added to CISA KEV on 2026-07-22. Unauthenticated attackers can obtain application login tokens and gain full admin access to the management server.
- High risk when the management interface is directly internet-exposed without Trusted Clients restrictions.
- Fixed in Jumbo HotFix R81.20 Take 158 / R82 Take 118 / R82.10 Take 36. Indicator:
Authentication method: application tokenin audit logs. - Kata Containers (CVE-2026-50540, fixed in 4.0.0): unvalidated
io.katacontainers.config_pathannotation allows loading a host TOML file, leading to root code execution on the host. - Keysight IxChariot (CVE-2026-49435): stack overflow enabling arbitrary code execution with admin privileges from a single packet; affects IxChariot, Hawkeye, IxTap, IxProbe, IxByPass.
- N-able N-central (CVE-2026-18577, added to KEV 2026-08-03): incomplete fix for CVE-2026-18556; auth bypass leading to admin account takeover, exploited in the wild.
- Black Hat research by HD Moore (runZero) found vulnerabilities—new and old—in HPE iLO, Supermicro IPMI, Dell iDRAC, and OpenBMC, including 2013's IPMI 2.0 auth flaw CVE-2013-4786, which still affects ~75,000 devices with offline-crackable passwords.
- Over 86,000 BMCs are internet-exposed; 54% have at least one critical vulnerability. Of ~126,000 internal-scan devices, 29% are affected.
- Exploitation enables out-of-band server control, persistence, and lateral movement, bypassing the OS. Vendor patches and full CVEs are still under coordinated disclosure.
- Metabase: upgrade self-hosted instances immediately; block unnecessary admin endpoints; rotate DB credentials and audit logs.
- BMC / out-of-band management: isolate management networks, enforce strong authentication, inventory exposure, monitor and follow vendor advisories.
- Check Point / SonicWall / N-able: apply Jumbo HotFix or corresponding patches; restrict public exposure of management interfaces.
- Microsoft cloud products: prioritize the August Patch Tuesday batch of CVSS 10.0 elevation-of-privilege fixes.
- Track CISA KEV and vendor advisories, prioritizing actively exploited items; audit logs for abnormal authentication, SQL injection signatures, and management-interface access.
Check Point SmartConsole auth bypass (CVE-2026-16232, CVSS 9.3)
CISA "Week of August 3" advisory (sb26-222) and recent KEV additions
| Product | ID | CVSS | |---|---|---| | Azure SQL Database (EoP) | CVE-2026-56162 | 10.0 | | Microsoft Teams (EoP) | CVE-2026-65667 | 10.0 | | Planetary Computer Pro (EoP) | CVE-2026-63508 | 10.0 | | Microsoft Entra (EoP) | CVE-2026-50481 | 9.9 | | Kata Containers (host code exec) | CVE-2026-50540 | 9.6 | | Keysight IxChariot (unauth RCE) | CVE-2026-49435 | 9.8 | | SonicWall SMA1000 | CVE-2026-15409 | 10.0 | | N-able N-central (auth bypass) | CVE-2026-18577 | 8.2 · KEV |
Hardware: widespread BMC exposure
Other hardware notes: recent Linux kernel use-after-free privilege escalation fixes; no new catastrophic physical chip defects reported in the past 24 hours.