← All briefings

Metabase · SAP NetWeaver and ABAP Platform · Progress Kemp LoadMaster

Date: 2026-08-11 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Today’s most critical new developments are two CVSS 10.0 SQL injection flaws in Metabase with confirmed active exploitation, a CVSS 9.8 unauthenticated memory corruption flaw in SAP NetWeaver ABAP (DIAG protocol), and a CISA advisory confirming ransomware gangs are actively exploiting SonicWall SMA1000 vulnerabilities. A new ransomware strain (StormEncryptor) linked to a former Medusa affiliate has been disclosed, and Gunra RaaS has been formally profiled by CISA. A supply-chain compromise of BdThemes WordPress plugins is also newly confirmed.


Critical Vulnerabilities

CVE-2026-72899 / CVE-2026-72898 — Metabase (Unauthenticated SQL Injection / Admin Takeover)

  • Severity: CVSS 10.0
  • EPSS: 0.0 (newly published; exploitation already confirmed in the wild)
  • Technical detail: Two distinct unauthenticated SQL injection paths. CVE-2026-72899 exploits field-filter (dimension) parameters on publicly shared cards or dashboards — no authentication required if a card is publicly shared. CVE-2026-72898 targets the /reset_password database endpoint, allowing an unauthenticated attacker to inject arbitrary SQL and gain full administrator access to the connected Metabase instance. Both flaws affect versions x.58.0–x.63.x across all release trains. Exposure is broad: any internet-facing Metabase instance with public sharing enabled or an accessible reset endpoint is at risk.
  • Exploitation status: Actively exploited in the wild. Heise Security reported admin-level attacks observed on 2026-08-10. BSI issued a critical advisory (WID-SEC-2026-2715).
  • Remediation: Upgrade immediately to x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, or x.63.5 depending on your release train. Disable public sharing on all cards/dashboards until patched. Treat any previously internet-exposed instance as compromised; review database query logs for anomalous SQL patterns. Rotate all database credentials accessible from Metabase.

CVE-2026-34265 — SAP NetWeaver and ABAP Platform (Unauthenticated Memory Corruption via DIAG Protocol)

  • Severity: CVSS 9.8
  • EPSS: 0.0 (newly published)
  • Technical detail: An unauthenticated attacker can exploit logical errors in DIAG protocol parsing to cause memory corruption, potentially leading to information disclosure or further impact. Affected versions span a wide range of kernel releases (7.22 through 9.19, including KRNL64NUC, KRNL64UC, and KERNEL variants), covering the majority of production SAP landscapes. The DIAG protocol is used for SAP GUI communication and is typically exposed on port 3200–3299 (dispatcher port). No authentication is required to trigger the flaw.
  • Exploitation status: No confirmed exploitation reported at time of publication; CVSS 9.8 and unauthenticated network vector make this a high-priority patch target.
  • Remediation: Apply SAP August 2026 Security Patch Day updates. Restrict DIAG port access to trusted SAP GUI client IP ranges at the network perimeter. Review SAP Security Note for this CVE via the SAP Support Portal.

CVE-2026-8037 — Progress Kemp LoadMaster (Command Injection, Actively Exploited)

  • Severity: Critical
  • EPSS: Previously reported
  • STATUS CHANGE: CISA and Bleeping Computer confirmed on 2026-08-10 that ransomware gangs are now actively exploiting this flaw. The CISA KEV remediation deadline was 2026-08-10. Any unpatched instance must be treated as actively targeted by ransomware operators.
  • Remediation: Patch immediately; restrict management interface to trusted IPs; hunt for post-exploitation indicators.

  • Severity: CVSS 9.9 (multiple CVEs)
  • EPSS: 0.0 (newly published)
  • Technical detail: A large batch of critical vulnerabilities was disclosed in Dokploy (self-hosted PaaS) prior to version 0.29.13. Issues include: command injection via unsanitized shell pipeline construction in backup/restore operations (CVE-2026-72733, CVE-2026-72738); arbitrary command execution by authenticated low-privilege members on the control-plane host (CVE-2026-72901, CVE-2026-72902); WebSocket handlers that authenticate sessions but do not authorize resource access (CVE-2026-72863); path traversal in certificate path handling (CVE-2026-72880); and shell metacharacter injection via file mounts (CVE-2026-72882). The attack surface is significant for any organization running Dokploy to manage containerized workloads.
  • Exploitation status: No confirmed exploitation; severity and breadth of issues warrant urgent patching.
  • Remediation: Upgrade Dokploy to 0.29.13 immediately. Restrict Dokploy management interfaces to trusted networks. Audit for unauthorized service modifications or unexpected scheduled tasks.

CVE-2026-48158 / CVE-2026-48159 / CVE-2026-48160 / CVE-2026-48161 — dai-shi React Libraries (Malicious Supply Chain Commits)

  • Severity: CVSS 9.3
  • EPSS: 0.0 (newly published)
  • Technical detail: Four npm packages maintained by dai-shi (use-context-selector, use-reducer-async, react-tracked, react18-use) contained malicious commits injected between 2026-05-18 and 2026-05-19 for a window of approximately 14–24 hours each. Any application that installed or updated these packages during that window may have incorporated malicious code. The malicious commits have since been removed, but downstream builds that consumed affected versions remain at risk.
  • Exploitation status: No confirmed exploitation reported; supply chain window was narrow but real.
  • Remediation: Audit package-lock.json and build artifacts for affected commit hashes (see EUVD entries for specific SHAs). Rebuild from clean sources using versions published after 2026-05-19 15:30 UTC. Rotate secrets accessible from affected build environments.

ONGOING:

  • CVE-2026-63077 (JetBrains TeamCity): Public PoC available; actively exploited — upgrade to 2026.1.3, hunt for .jspws webshells.
  • CVE-2026-14526 (WordPress AI Copilot): EPSS 0.61 — update or deactivate; patch still required.
  • CVE-2026-64638 (WordPress Core): Apply core patch; enforce CSP on login pages.
  • CVE-2026-64637 (Plesk): Upgrade to 18.0.80.1; enforce MFA.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.
  • CVE-2026-16232 (Check Point SmartConsole): Actively exploited — treat unpatched instances as compromised.

European Advisories

BSI published multiple new and updated advisories on 2026-08-10. New critical/high advisories include:

  • WID-SEC-2026-2715 (Metabase): Covered in Critical Vulnerabilities above.
  • WID-SEC-2026-2719 (Flowise, UNPATCHED): An authenticated attacker can bypass security controls. No patch is currently available. Restrict Flowise access to trusted users and networks; monitor for exploitation.
  • WID-SEC-2026-2716 (GIMP, UNPATCHED): A remote unauthenticated attacker can achieve code execution. No patch available. Avoid opening untrusted image files in GIMP; consider sandboxing.
  • WID-SEC-2026-2713 (Sonatype Nexus Repository Manager): Multiple authenticated vulnerabilities enabling data disclosure, code execution, and privilege escalation. Apply available vendor patches; restrict Nexus to internal networks.
  • WID-SEC-2026-2711 (IBM DB2): Multiple flaws enabling RCE, privilege escalation, security bypass, DoS, and information disclosure. Apply IBM DB2 security patches.
  • WID-SEC-2026-2708 (ClamAV): Remote unauthenticated DoS and information disclosure. Update ClamAV to the latest release.
  • WID-SEC-2026-2706 (D-Link DWR-M961): Multiple flaws enabling admin-level RCE and DoS — update firmware to 1.1.5_C1_202607071108 (previously reported; advisory updated).

BSI also issued updates for Linux Kernel, Red Hat Enterprise Linux (DBI/perl-GD, Pillow), Atlassian suite, Ruby, HCL BigFix, Django, Bouncy Castle, Xen, ffmpeg, libssh2, ISC BIND, Mozilla Firefox/Thunderbird, Red Hat Ansible Automation Platform, Netty, CPython, and X.Org/Xwayland. Apply vendor patches per your standard patch cycle; critical items are detailed in Critical Vulnerabilities.


Active Threats and Campaigns

NEW — Gunra Ransomware (RaaS): CISA published advisory AA26-222A on 2026-08-10 profiling Gunra, a ransomware-as-a-service operation that emerged in 2025 and expanded to affiliate-based RaaS in 2026. Gunra employs double extortion — encrypting data and threatening publication on a dedicated leak site. Targets include government, critical infrastructure, and enterprise organizations. Review the CISA advisory for TTPs and IOCs; apply recommended mitigations.

NEW — StormEncryptor Ransomware (Storm-1175): Microsoft disclosed that Storm-1175, a financially motivated actor with China nexus previously associated with Medusa ransomware, is now deploying a new C++-based ransomware strain appending .encrypted to files. This represents a tooling shift and may indicate operational restructuring. Confidence in attribution is assessed as moderate (Microsoft sourced).

NEW — BdThemes WordPress Supply Chain Compromise: A threat actor compromised BdThemes’ upstream infrastructure and modified a remote JSON feed delivered to administrators’ browsers, resulting in creation of rogue WordPress admin accounts on affected sites. Organizations using BdThemes plugins should audit admin accounts immediately and verify plugin integrity.

NEW — SonicWall SMA1000 Active Ransomware Exploitation (CVE-2026-8037 and related): CISA confirmed ransomware gangs are actively exploiting SonicWall SMA1000 flaws. See Critical Vulnerabilities for remediation.

ONGOING — Aeternum Botnet (Blockchain C2): Unit 42 published analysis of the Aeternum loader using Polygon blockchain smart contracts for decentralized C2. No new IOCs beyond the published report; block known Polygon RPC endpoints at perimeter where operationally feasible.

ONGOING — Kimsuky AI-Assisted Phishing/Malware Development: No new developments; brief staff on AI-enhanced spearphishing.

ONGOING — Head Mare / TrueConf supply chain: Backdoored installers in circulation; verify hashes before deployment.


Security News and Context

  • SonicWall SMA1000 / Progress LoadMaster actively exploited: Both confirmed by CISA and Bleeping Computer as under active ransomware exploitation — see Critical Vulnerabilities and Recommended Actions. (Bleeping Computer)
  • Valve/Steam data breach: Valve is notifying European Steam hardware customers that personal data was stolen after attackers compromised shipping partner CEVA Logistics. (Bleeping Computer)
  • GCP Apigee cross-tenant data exfiltration (now patched): Tenable disclosed a confused-deputy flaw in Google Cloud Apigee allowing cross-tenant GCS object reads; Google has remediated. (Tenable)
  • Passkey attacks demonstrated: Three independent research efforts showed practical bypasses of passkey protections without breaking underlying cryptography — review passkey deployment configurations. (The Hacker News)

  1. Metabase (CVE-2026-72899 / CVE-2026-72898): Patch to the fixed release for your train immediately; disable public sharing; rotate database credentials; treat exposed instances as compromised.
  2. SAP NetWeaver ABAP (CVE-2026-34265): Apply SAP August 2026 Security Patch Day updates; restrict DIAG ports (32xx) to trusted SAP GUI client IPs.
  3. SonicWall SMA1000: Patch immediately — ransomware gangs are actively exploiting; isolate unpatched appliances from the network.
  4. Dokploy (multiple CVEs): Upgrade to 0.29.13; restrict management interface; audit for unauthorized changes.
  5. dai-shi React supply chain (CVE-2026-48158–48161): Audit builds for affected commit hashes; rebuild from clean sources; rotate secrets from affected CI/CD environments.
  6. Flowise (WID-SEC-2026-2719, unpatched): Restrict to trusted users/networks; monitor for exploitation until a patch is available.
  7. GIMP (WID-SEC-2026-2716, unpatched): Avoid processing untrusted image files; sandbox GIMP where possible.
  8. BdThemes WordPress plugins: Audit all WordPress admin accounts on sites using BdThemes plugins; remove unauthorized accounts; verify plugin file integrity.
  9. Gunra RaaS: Review CISA advisory AA26-222A for TTPs and IOCs; validate backup integrity and offline backup availability.
  10. Continue remediation of previously reported items: CVE-2026-63077 (TeamCity), CVE-2026-8037 (LoadMaster), CVE-2026-0257 (PAN-OS), CVE-2026-16232 (Check Point), CVE-2026-14526 (WordPress AI Copilot), Bouncy Castle FIPS, D-Link DWR-M961, Wazuh, Plesk.