A Metabase 10.0 Zero-Day, N-central Hotfix 2 & Kemp on KEV (08/08/2026)
- › Metabase disclosed a CVSS 10.0 flaw already exploited as a zero-day, giving unauthenticated attackers admin access, and it carries no CVE identifier.
- › N-able issued a second hotfix for N-central as attackers reached managed systems and established persistence, the third round of fixes in nine days.
- › CISA added a critical Progress Kemp LoadMaster flaw to its Known Exploited Vulnerabilities catalog after 792 reported exploit attempts.
- › The Head Mare group breached TrueConf and replaced client installers with backdoored versions.
- › Attacker-controlled instructions can make Atlassian's Rovo assistant send Jira and Confluence data to an outside server, and only one of the two reported routes is confirmed closed.
Saturday is usually quiet and this one is not. Metabase has a maximum-severity flaw that was exploited before anyone knew it existed, and it does not even have a CVE number yet. N-able is on its third round of N-central fixes in nine days while attackers keep moving further into customer environments. The pattern in both is a fix arriving after the adversary already has what they came for.
Top 5 Critical Security Alerts
1. A Metabase 10.0 Was Exploited Before Disclosure
Metabase warned that a maximum-severity flaw in its business intelligence and data visualization software has been exploited in the wild as a zero-day. The bug scores 10.0 and allows an unauthenticated remote attacker to gain administrative access. It does not currently carry a CVE identifier. The Hacker News
Operator Note: Business intelligence platforms hold a query path to every database somebody wanted a dashboard for, which makes admin access there worth more than admin access to most single applications. The missing CVE also means your scanner may not flag it, so treat this as a manual hunt.
2. N-able Ships Hotfix 2 as Attackers Persist on Managed Systems
N-able released another round of N-central hotfixes as part of its investigation into ongoing exploitation, saying it is proactively expanding protections in response to continued monitoring of threat actors. Attackers have reached managed systems and established persistence. The Hacker News
Operator Note: This is the third fix in nine days on the same flaw, and each one has been followed by confirmation the attackers got further. Patching is necessary here and it is not the same as being clear, which is what we take apart in incomplete patches.
3. Kemp LoadMaster Joins KEV After 792 Exploit Attempts
CISA added a critical Progress Kemp LoadMaster flaw to its Known Exploited Vulnerabilities catalog on Friday, following reports of active exploitation. Researchers logged 792 reported exploit attempts. The Hacker News
Operator Note: A load balancer sits in front of the applications you care about and terminates their encrypted connections, so compromise there is a position on the traffic rather than a foothold on a host. Anyone with a Kemp appliance should treat this as a weekend job.
4. TrueConf Installers Were Replaced With Backdoored Versions
The Head Mare group exploited unpatched TrueConf video conferencing servers and replaced the client installers with malicious versions delivering backdoors. BleepingComputer
Operator Note: The victim organization ran the vulnerable server and its own users downloaded the payload from it, trusting the source because it was internal. An unpatched server that distributes software is a distribution channel for whoever owns it.
5. Atlassian Rovo Can Be Talked Into Exfiltrating Your Wiki
Two security firms independently found that attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data available to the signed-in user and send it to an outside server. Only one of the two routes is confirmed closed. The Hacker News
Operator Note: Rovo reads with the permissions of whoever invoked it, and a Jira ticket is text a stranger can write. The exposure scales with how broadly your Confluence is readable internally, which in most companies is very broadly.
Additional Security Alerts
Vulnerabilities
- CSS in an email can reach the webmail interface around it: Researchers demonstrated chains across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that capture passwords, take over third-party accounts, and leak tokens. The Hacker News
Emerging Security Technologies
- Anthropic makes Claude Code Auto Mode the default: From August 14 the classifier that reviews commands becomes the default for Pro, Max, and Team plans. In testing it caught 89% of dangerous commands against 13.6% for human reviewers. The Decoder
- Developers are asking AI coding vendors for secure defaults: Researchers measuring developer sentiment found security and privacy defaults at the top of the request list for Anthropic, OpenAI, Cursor, and peers. The Register
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.