Metabase Zero-Day (CVSS 10.0) Under Active Exploitation
Critical Metabase BI tool zero-day (CVSS 10.0) exploited in the wild, hitting Framework and Tally. Attackers pivot via database credentials stored in Metabase. Framework confirmed customer data exposed. Clear IoCs and remediation steps available. Demands immediate action from enterprise teams.
Sources (3)
Updated Aug 10, 2026