logo

Atlassian Rovo, Metabase, LoadMaster zero-days & active exploitation

ID: 90f92de4-a716-530b-b236-ad202397ffbb

STIX ID: report--90f92de4-a716-530b-b236-ad202397ffbb

Feed Name: defend.network

Threat Score
90/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

Author: defend.network

...
...

### Executive Summary — Multiple high-risk, actively exploited vulnerabilities were reported across widely used enterprise tools: an Atlassian Rovo prompt-injection enabling data exfiltration, a Metabase unauthenticated admin zero-day (CVSS 10.0) tied to confirmed breaches, and a Progress Kemp LoadMaster command-injection (CVE-2026-8037) added to CISA KEV after hundreds of observed exploit attempts; additional threats include CSS-based webmail credential theft and persistence on N-able N-central-managed systems, with recommended immediate patching, isolation, and forensic review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.