A critical zero-day vulnerability in Metabase has been exploited by attackers, granting them admin access and allowing the theft of sensitive data. The flaw, which carries a CVSS score of 10.0, enables unauthenticated attackers to inject arbitrary SQL into the Metabase application database1. Metabase has confirmed that its cloud service was among the victims, highlighting the severity of the issue. The vulnerability was exploited before a patch was available, underscoring the importance of prompt action to mitigate its impact. The fact that attackers were able to exploit this flaw before it was discovered by defenders means that the window for patching is rapidly closing. This incident matters to practitioners because it underscores the need for immediate assessment of exposure to this vulnerability, in order to prevent similar breaches and protect sensitive data.