VORANT. Threat Intelligence Sign in Get the full feed

ANSSI Flags Metabase SQLi, npm Supply-Chain Worm

high threat technology

CERT-FR's weekly bulletin reports active exploitation of a critical Metabase SQLi flaw, a Shai-Hulud npm worm reinfecting AntV packages, and dozens of actively exploited critical CVEs.

CERT-FR's weekly activity bulletin (week 37, 2026) rounds up the most significant vulnerabilities disclosed between 7-13 September 2026 and flags two active incidents. The first is a critical, unauthenticated SQL-injection vulnerability in Metabase (referenced as CVE-2026-72898 in related CERT-FR material) that grants attackers administrator rights on the instance; CERT-FR states it is aware of numerous real-world Metabase compromises and provides detection signatures (a POST to /api/session/reset_password returning HTTP 400 followed by a GET to /api/user/current returning HTTP 200) along with remediation steps including revoking all sessions, rotating API keys and database credentials, and auditing admin accounts.

The second incident is a supply-chain compromise: on 7 September 2026 several npm packages published under the AntV namespace (feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, bmc-translate-utils@1.1.1) were found trojanized with a known variant of the Shai-Hulud self-propagating worm, per Aikido Security's blog. This marks a resurgence of the Shai-Hulud npm worm campaign; defenders using these package/version combinations should treat them as compromised and follow standard npm supply-chain incident response (credential rotation, dependency pinning review, CI/CD secret rotation).

Separately, the bulletin catalogs a large volume of vulnerability advisories issued that week, many carrying CVSS scores of 9.0-10 and flagged by NVD as actively exploited, including flaws in GitLab CE/EE, Adobe Commerce/Magento, IBM Db2, Microsoft Edge and Windows, Roundcube Webmail, N-Able N-Central, ConnectWise ScreenConnect, Citrix NetScaler, MikroTik RouterOS, and JFrog Artifactory. A further long tail of critical, not-yet-confirmed-exploited CVEs spans SAP, Adobe ColdFusion, Check Point Spark/Security Gateway, Palo Alto Prisma Access Browser, Google Chrome, Android, and dozens of Windows/Office RCE bugs from Microsoft's September Patch Tuesday. Defenders should prioritize patching the confirmed-exploited items first, then work through the broader critical list per standard risk-based patch management.

Mentioned in this report

Vulnerabilities CVE-2018-1273KEVCVE-2026-19490KEVCVE-2026-28606CVE-2026-41157CVE-2026-42016KEVCVE-2026-42018KEVCVE-2026-44756CVE-2026-48273CVE-2026-49921CVE-2026-54433CVE-2026-58240CVE-2026-58822CVE-2026-65669CVE-2026-66768CVE-2026-67277KEVCVE-2026-68839CVE-2026-69276CVE-2026-69408CVE-2026-69414CVE-2026-69854CVE-2026-72898KEVCVE-2026-75650KEVCVE-2026-75746CVE-2026-78445CVE-2026-78509CVE-2026-78510CVE-2026-79282CVE-2026-79290CVE-2026-81963KEVCVE-2026-84869KEVCVE-2026-85046KEVCVE-2026-85102CVE-2026-85103CVE-2026-85706KEVCVE-2026-85880KEVCVE-2026-86060KEVCVE-2026-86218KEVCVE-2026-87438CVE-2026-87544CVE-2026-87719

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-039

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free