Metabase published a critical advisory on 6 August. Maximum severity, ten out of ten: an unauthenticated SQL injection in the password reset endpoint that handed an attacker administrator access to a self-hosted instance without a login. By 11 August the US government had added it to its list of vulnerabilities known to be exploited and given its own agencies three days to fix it.
Mathspace, the online maths platform used in schools across Australia and New Zealand, ran a self-hosted Metabase for internal reporting. Someone got into it on 10 August. On 27 August they downloaded the Australian reporting database. On 29 August Mathspace patched, prompted by a later notice from Metabase rather than the original advisory. On 3 September it confirmed the intrusion and took the system offline, and on 4 September it told schools and regulators.
1,079,819 people. Students, parents and guardians, and school staff. Names, email addresses, usernames, user type, and account metadata such as last login and date joined. No passwords, no tokens, no academic records, which is the better version of this story.
The sentence that matters
Mathspace's own write-up contains the line every IT manager should read twice: "Our existing -notification process did not identify and escalate that advisory for action."
That is not a company with no patching. It is a company with a process that did not know Metabase was in scope. Which is the normal condition. Reporting tools, dashboards, wikis and ticketing systems get stood up by whoever needed them, do a useful job for years, and never make it onto the list of things patched on a schedule, because nobody thinks of them as internet-facing. Then a ten out of ten lands on a Thursday and the process that would have caught it is looking at Windows and the firewall.
Four days from advisory to intrusion. Twenty-three days from advisory to patch. Attackers were working from the same bulletin Mathspace's process missed, and they were faster.
Your insurer is reading the same timeline
policies increasingly carry patch exclusions: clauses that decline losses tied to a vulnerability above a severity threshold where a patch was available and not applied within a set window. Coalition's Tiago Henriques has said at least one well-known insurer excludes losses where the vulnerability scores above eight and the patch has been out for three weeks or more.
Three weeks is 21 days. Mathspace's gap was 23. Whether that clause sits in any particular policy is a question for the policy, and Coalition itself argues the exclusions are too broad, since only about one in a hundred qualifying vulnerabilities is ever exploited. But the direction is clear. Chubb sells an endorsement that shares the loss on a sliding scale at 45, 90, 180 and 365 days. Australian underwriters are scanning your perimeter at renewal and comparing what they find with what you declared. A missed advisory on a reporting tool is no longer only a security problem. It can be the difference between a covered loss and an uncovered one.
What to do with this
Build the list. Every self-hosted tool, who owns it, where its security advisories are published, and who is subscribed. If nobody is subscribed, that is the finding. Metabase told the world on 6 August. The information was free.
Set a clock for critical severity. The asks for internet-facing services to be patched within 48 hours when an exploit exists. Whether you adopt that number or another one, write it down, because the insurer will ask for the number and then check.
Look at yourself from outside. An external scan of your own perimeter, run regularly, finds the Metabase you forgot. It is the same view the attacker had and the same view the underwriter is buying.
Read the policy. Find the word "patch" in your cyber cover and understand what the clause around it says about timeframes. If the answer is uncomfortable, better to learn that now than in the claim.
And if you run a school, or you are a parent: the stolen fields are exactly what a convincing "message from the school" needs. A child's name, a parent's email, and a platform the school genuinely uses. Mathspace's advice is right. Check unexpected messages independently, and do not hand over passwords or codes because a message asked.
Was the Mathspace vulnerability a zero-day?
It was exploited before the public advisory, and self-hosted instances on version 0.58 and above were affected. Mathspace's intrusion came four days after the fix was published, so for Mathspace it was a missed patch rather than a .
Does a patch exclusion apply to every unpatched system?
It depends on the wording. The clause Coalition describes triggers on a severity above eight and a patch available for three weeks or more. Read your own policy. The thresholds differ between insurers.



