Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIMetabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has disclosed a critical zero-day vulnerability with a maximum CVSS score of 10.0 in its business intelligence platform that is being actively exploited in the wild. The flaw allows unauthenticated remote attackers to execute arbitrary SQL injection attacks against the Metabase application database, potentially granting unauthorized administrative access without any authentication require
AICritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
A critical vulnerability (CVE-2026-59774) in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read arbitrary files accessible to the service account by exploiting crafted Org-mode markup in public repositories. The flaw carries a CVSS score of 9.8 and requires no authentication or special privileges to exploit. Organizations running affected versions should immediately upgr
AIAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has issued critical security patches for Campaign Classic, addressing CVE-2026-48449, a maximum-severity vulnerability with a CVSS score of 10.0. The flaw, stemming from incorrect authorization, enables arbitrary code execution without requiring user interaction, posing significant risk to enterprises using this marketing automation platform.
AICritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has released version 24.10.8 to address a critical DHCPv6 vulnerability (CVE-2026-53921) with a CVSS score of 9.8 that allows unauthenticated attackers to execute arbitrary code with root privileges. The flaw involves a stack buffer overflow in the odhcpd service that can be exploited remotely through crafted DHCPv6 packets. The update also patches additional remotely exploitable vulnerabi
AICisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Cisco has issued critical security updates for a maximum-severity authentication bypass vulnerability (CVE-2026-20182, CVSS 10.0) in Catalyst SD-WAN Controller and Manager products. The flaw, affecting peering authentication mechanisms, has been actively exploited in limited attacks to gain unauthorized administrative access. Organizations using these SD-WAN solutions should prioritize immediate p
