Daily briefing · August 10, 2026
Metabase Under Active Exploitation and Dokploy Hit by Multiple Critical RCE Chains
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
August 10, 2026 brings a high-alert day with one vulnerability already observed in active exploitation by VulnCheck ahead of any official CISA confirmation: a CVSS 10.0 SQL injection in Metabase that hands attackers unauthenticated administrator access. Alongside it, a second critical Metabase flaw, a remote code execution in the Fabrik Joomla extension, dangerous deserialization issues in Red Hat OpenShift AI components, and four separate critical command-injection vulnerabilities in the self-hosted PaaS platform Dokploy complete a day that demands immediate patching attention across web analytics, ERP, and container orchestration stacks.
Today’s brief
- ACTIVE EXPLOITATION: CVE-2026-72898 in Metabase (CVSS 10.0) flagged by VulnCheck before CISA — unauthenticated SQL injection granting full admin access
- Dokploy is hit by four critical RCE/command-injection CVEs (9.9) affecting low-privilege or authenticated users on self-hosted PaaS deployments
- Fabrik for Joomla and ERPNext carry unauthenticated or low-auth RCE at CVSS 10.0/9.9 — open-source business tools are in the crosshairs
- Brazil is a ransomware battleground: five new victims recently claimed including a government portal and two education targets
Critical highlights
1
VulnCheck detected active exploitation of this CVSS 10.0 flaw in Metabase before CISA issued any alert — an unauthenticated attacker can inject arbitrary SQL through the '/reset_password' endpoint to seize full administrator control. Any publicly exposed Metabase instance must be treated as compromised until patched.
2
The Fabrik extension for Joomla (versions below 4.6.7) allows an unauthenticated attacker to execute arbitrary code via the ajax_calc feature of the calc plugin. Joomla-based sites using Fabrik are fully exposed with no authentication barrier whatsoever.
3
A second CVSS 10.0 Metabase vulnerability allows unauthenticated SQL injection through publicly shared cards or dashboards that expose a field-filter (dimension) parameter. Public-facing Metabase dashboards represent a silent attack surface that may already be targeted given the companion exploitation activity in CVE-2026-72898.
4
ERPNext versions prior to 15.118.0 and 16.29.0 expose unrestricted Jinja template globals to authenticated users with common operational roles, enabling server-side template injection and likely remote code execution. The low privilege bar makes this highly exploitable in multi-tenant ERPNext deployments.
5
A critical deserialization flaw in Feast (used in Red Hat OpenShift AI 3.3) allows attackers to store malicious user-defined functions serialized with the 'dill' library, leading to unauthenticated arbitrary code execution on the feature server. Default configurations are fully vulnerable, making this a high-priority patch for any AI/ML pipeline using Feast.
6
The MaaS API in Red Hat OpenShift AI trusts the HTTP headers 'X-MaaS-Username' and 'X-MaaS-Group' verbatim, allowing any pod in the cluster to forge identity and escalate privileges through the Kuadrant AuthPolicy gateway. An attacker with minimal cluster foothold can abuse this to mint tokens and move laterally at will.
7
In Dokploy prior to 0.29.13, the registry password field is interpolated directly into a remote shell command, enabling an authenticated user to execute arbitrary commands on local or SSH-connected servers. PaaS administrators who have not upgraded are exposed to full host takeover from within their own platform.
8
Also in Dokploy prior to 0.29.13, an authenticated low-privilege member can execute arbitrary commands on the control-plane host by supplying a crafted volumeName field to the volume backup API. The low privilege requirement drastically widens the potential attacker pool on shared Dokploy instances.
9
From Dokploy 0.29.2 through 0.29.12, a logic flaw in schedule creation allows a member with access to one application to attach a server-level scheduler to a different service, bypassing owner/admin authorization checks and enabling host-level command execution. This authorization bypass is particularly dangerous in multi-tenant Dokploy environments.
10
In Dokploy 0.28.8 and earlier, shell metacharacters in the filePath field of file mounts are executed over SSH on the configured remote managed server, delivering direct host RCE from the web interface. This is the fourth critical chain in Dokploy this cycle — organizations running any version below 0.29.13 should treat the platform as fully compromised until updated.
Ransomware today
Ransomware groups have recently claimed multiple Brazilian victims across sensitive sectors: Chat Jurídico (Professional Services) was hit by direwolf, Intranet Gov Brasil (Government & Defense) by thegentlemen, brdigital.net.br and uva.edu.br (Technology and Education respectively) by L Group, and Alya Construtora (Manufacturing) by ransomhouse. Over the past 30 days, lockbit5 leads activity with 24 recorded attacks — all in Brazil — followed by Section9 with 6, and Global Secret Group with 4, painting a picture of concentrated, Brazil-focused ransomware pressure.
Chat Jurídico BRdirewolf · Professional Services
Intranet Gov Brasil BRthegentlemen · Government & Defense
brdigital.net.br BRL Group · Technology
uva.edu.br BRL Group · Education
Alya Construtora BRransomhouse · Manufacturing
lockbit5 24Section9 6Global Secret Group 4thegentlemen 3L Group 2ransomhouse 2
Active groups & APTs
Several threat actors and APT groups have been flagged as active or recently updated in threat intelligence feeds, including linkc, Equation, Darkhotel (attributed to North Korea), karakurt, LeakBazaar, and apt73. While no specific victims are currently attributed to these groups in this cycle, their presence in active monitoring indicates potential preparatory or reconnaissance activity that warrants watchful detection posture.
Brazil focus
Brazil is facing an unusually dense wave of targeted ransomware intrusions across a wide spectrum of sectors. Recent victims include Chat Jurídico, Intranet Gov Brasil, brdigital.net.br, uva.edu.br, Alya Construtora, PontoBR Sistemas, cesmac.edu.br, and eSysTech — spanning government, education, technology, and manufacturing. The concentration of attacks by groups such as L Group, thegentlemen, ransomhouse, spacebears, krybit, and Orova underscores that Brazilian organizations remain a priority target for multiple ransomware operators simultaneously.
Chat Jurídicodirewolf · Professional Services
uva.edu.brL Group · Education
Alya Construtoraransomhouse · Manufacturing
brdigital.net.brL Group · Technology
Intranet Gov Brasilthegentlemen · Government & Defense
PontoBR Sistemasspacebears · Technology
cesmac.edu.brkrybit · Education
eSysTechOrova · Technology
Today’s recommendation: Organizations running Metabase should isolate or take down public-facing instances immediately and apply patches without delay, treating CVE-2026-72898 as a confirmed active threat; teams using Dokploy must upgrade to 0.29.13 or later to close four concurrent critical command-injection vectors before any of them is weaponized.
Given the breadth of today's critical vulnerabilities spanning analytics tools, ERP systems, PaaS platforms, and AI/ML infrastructure, now is the right moment to map and validate which of these technologies exist in your environment — even in shadow IT or development pipelines — to understand your true exposure before attackers do.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →