Back to Markets
ZERO-DAYLIVEMetabaseSQLiZero-DayKEVauto-generated

Will Metabase SQLi zero-day be added to CISA KEV by September 2026?

95%
YES
5%
NO
0 predictions
YES
NO
100%80%60%40%20%0%
30d25d20d15d10d5dnow

Market Overview

AI GENERATED

Metabase disclosed a critical SQL injection zero-day (CVE unspecified) being actively exploited in the wild for customer data theft, with confirmed victims including Framework and Tally (Bleeping Computer). This is an active, unpatched exploitation scenario with material business impact.

Primary Source

Resolution Criteria

Official CISA Known Exploited Vulnerabilities (KEV) Catalog listing naming the Metabase SQLi flaw and confirming inclusion before Sept 30, 2026. Alternatively, Metabase official security advisory + Bleeping Computer or CISA confirmation of active wild exploitation and vendor patch release.

Market Info

ClosesSeptember 7, 2026
CreatedAug 8, 2026
CategoryZero-Day
Created by@ThreatOdds
Creator accuracy0%
ResolutionCommunity vote + moderator
StatusLIVE

MARKET STATS

Total Predictions0
ClosesSeptember 7, 2026
ResolutionCommunity + Moderator
CategoryZero-Day
Beta Feedback