A critical SQL injection vulnerability in Metabase has been exploited in zero-day attacks, resulting in the theft of customer data from instances of Framework and Tally. The vulnerability, which has not been publicly disclosed with a CVE number, allows attackers to inject malicious SQL code and extract sensitive information. The attacks have been observed in the wild, with multiple instances being breached. The fact that these attacks are already happening means that the window for patching is rapidly shrinking1. Metabase users are advised to take immediate action to assess their exposure and apply any available patches to prevent further breaches. The exploitation of this vulnerability highlights the importance of prompt patch management and vulnerability assessment. So what matters to practitioners is that they must assess their Metabase instances immediately to prevent data theft.