Patch Metabase this morning, then rotate every database login it holds

The news: CISA flagged CVE-2026-72898 as exploited on August 11, with a federal fix deadline of August 14. It is a CVSS 10.0 unauthenticated SQL injection in Metabase, and exploit code went public a day earlier.

Why it matters: The flaw sits in the reset-password endpoint, which answers before login, so SSO will not close it. Admin access exposes the saved connection credentials for every database Metabase queries. Shodan counts about 2,500 exposed instances, and those credentials still work after you patch.

What to do: Patch your branch this morning, then kill sessions and rotate every database credential Metabase holds.

The person who promised you those terms just left

OpenAI's revenue chief, Denise Dresser, is out after about nine months. Dali Rajic replaces her, arriving from Wiz by way of Zscaler and AppDynamics. It is the second senior exit in a week, and an IPO is close. Commitments that live in email rarely survive a change of account leadership. If your OpenAI deal carries verbal promises on price, capacity, or support, paper them this week.

Cisco confirmed the attacks and published nothing to hunt with

CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and Secure FTD firewalls through the remote access SSL VPN service. Cisco shipped fixes on August 11 and confirmed live exploitation. The advisory carries no indicators of compromise, so there is nothing to hunt for. That leaves one symptom: a firewall that reloaded with no change ticket behind it. Pull reload history on your VPN concentrators back through early August.

Watch This

The EU Cyber Resilience Act starts a 24-hour reporting clock on September 11. Vendors selling connected products into the EU get one day to report active exploitation to ENISA. Advisories will arrive faster and in larger numbers, and most IT teams have not named who reads them.

Rotating credentials after a patch is the step that gets skipped, because no one owns it. If you run IT or security at a $100M+ company, DoGood network members are the peers to ask who owns it at their company.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.