ANSSI Flags Metabase SQLi, npm Supply-Chain Worm
CERT-FR's weekly bulletin reports active exploitation of a critical Metabase SQLi flaw, a Shai-Hulud npm worm reinfecting AntV packages, and dozens of actively exploited critical CVEs.
CERT-FR's weekly activity bulletin (week 37, 2026) rounds up the most significant vulnerabilities disclosed between 7-13 September 2026 and flags two active incidents. The first is a critical, unauthenticated SQL-injection vulnerability in Metabase (referenced as CVE-2026-72898 in related CERT-FR material) that grants attackers administrator rights on the instance; CERT-FR states it is aware of numerous real-world Metabase compromises and provides detection signatures (a POST to /api/session/reset_password returning HTTP 400 followed by a GET to /api/user/current returning HTTP 200) along with remediation steps including revoking all sessions, rotating API keys and database credentials, and auditing admin accounts.
The second incident is a supply-chain compromise: on 7 September 2026 several npm packages published under the AntV namespace (feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, bmc-translate-utils@1.1.1) were found trojanized with a known variant of the Shai-Hulud self-propagating worm, per Aikido Security's blog. This marks a resurgence of the Shai-Hulud npm worm campaign; defenders using these package/version combinations should treat them as compromised and follow standard npm supply-chain incident response (credential rotation, dependency pinning review, CI/CD secret rotation).
Separately, the bulletin catalogs a large volume of vulnerability advisories issued that week, many carrying CVSS scores of 9.0-10 and flagged by NVD as actively exploited, including flaws in GitLab CE/EE, Adobe Commerce/Magento, IBM Db2, Microsoft Edge and Windows, Roundcube Webmail, N-Able N-Central, ConnectWise ScreenConnect, Citrix NetScaler, MikroTik RouterOS, and JFrog Artifactory. A further long tail of critical, not-yet-confirmed-exploited CVEs spans SAP, Adobe ColdFusion, Check Point Spark/Security Gateway, Palo Alto Prisma Access Browser, Google Chrome, Android, and dozens of Windows/Office RCE bugs from Microsoft's September Patch Tuesday. Defenders should prioritize patching the confirmed-exploited items first, then work through the broader critical list per standard risk-based patch management.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-039
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free