HiddenMerit Morning Post · Issue 76

📊 HiddenMerit Morning Post · Issue 76

Focus on Database Frontiers, Practical Insights for DBAs August 14, 2026 | 5 Selected Global Breaking News

01|Metabase Zero‑Day CVE-2026-72898 (CVSS 10.0): CISA Mandates Fix by August 14

On August 11, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the critical Metabase SQL injection vulnerability (CVE-2026-72898) to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to remediate by August 14. The vulnerability has a CVSS score of 10.0 (highest risk level), with confirmed active exploitation in the wild. Attackers can inject arbitrary SQL through the /reset_password endpoint without authentication, gaining administrator privileges and accessing all connected data sources. Third‑party organisations including Framework, Tally, and LexisNexis have already been compromised through this vulnerability.

Remediation: Affected versions cover branches 1.58 through 1.63, requiring upgrades to 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, or 1.63.5. Self‑hosted instances must be manually upgraded. Indicators of Compromise (IoCs): Watch for access patterns where POST /api/session/reset_password returns 400 followed immediately by GET /api/user/current returning 200. After patching, immediately revoke active sessions, review administrator accounts, and rotate all credentials to connected databases.

  • DBA Perspective: CISA’s two‑day remediation deadline indicates this vulnerability has been weaponised. Metabase typically holds high‑privilege database connections – once compromised, it can directly access downstream production databases. All DBAs using Metabase self‑hosted instances should immediately upgrade and rotate credentials. A CVSS 10.0 vulnerability should not be treated as “fix soon” but as an “attack in progress.”

02|OceanBase Launches First External Funding Round: Targeting RMB 2‑3 Billion, Annualized Revenue Exceeds RMB 1.4 Billion, Benchmarking “China’s Databricks”

Ant Group’s distributed database company OceanBase officially launched its Series A funding round on July 29, targeting approximately RMB 2‑3 billion, and has already engaged with multiple leading investment institutions. This marks the first time OceanBase has introduced external funding since its establishment. In March 2024, OceanBase established an independent board of directors with a CEO‑accountable governance structure, laying the foundation for independent operations.

Key Data: In 2026, OceanBase’s annualized revenue has exceeded RMB 1.4 billion, representing approximately 70% year‑on‑year growth. Customers include Bank of Communications, China Mobile, and thousands of other enterprises. According to CCID Consulting, OceanBase ranked first in China’s distributed database on‑premises deployment market share in 2025, and was positioned in the “Leader” quadrant of vendor competitiveness assessment, ranking first in product capability. Currently, one‑third of central SOEs have deployed core systems on OceanBase, covering critical industries including transportation, energy, and telecommunications.

Strategic Benchmarking: Bloomberg has referred to OceanBase as “China’s Databricks.” OceanBase is evolving from a distributed database toward an AI data platform. The “lakehouse‑integrated” AI database released in June has been tested in dozens of customer scenarios, with continued expansion across government, enterprises, and critical industries – from financial cores to thousands of industries.

  • DBA Perspective: OceanBase’s first external funding is a landmark event for domestic databases moving toward “market‑oriented independent operations.” The annualized revenue exceeding RMB 1.4 billion and 70% growth validate the commercial maturity of domestic distributed databases. Benchmarking against Databricks means its strategic direction is extending from a “database company” to an “AI data platform” – DBA skills need to expand from “distributed database operations” to “AI data platform architecture and multi‑modal data management.”

03|Dameng Strategic Focus Shifts to Next‑Generation All‑in‑One: Driving Domestic Databases from “Usable” to “Good‑to‑Use”

On August 6, Dameng stated during an investor research visit that after achieving breakthroughs in key core technologies such as shared storage clusters, its strategic focus is gradually shifting toward the next‑generation database all‑in‑one business. Through deep integration and collaborative optimisation of hardware and software, the product aims to deliver higher performance, easier deployment, and higher availability data infrastructure, precisely matching the dual demands of autonomous control and extreme performance in key industries such as finance, energy, and telecommunications.

[quads id="805"]

Dameng stated it will focus on building a data foundation for the AI era, driving domestic databases from “usable” to “good‑to‑use” through technological innovation, and comprehensively empowering digital transformation across industries. In early August, Dameng partnered with CCF NCCA 2026 to launch the “Digital Intelligence Industry Innovation Joint Development Plan” and the “Database Industry Ecosystem Construction Joint Initiative,” signalling efforts to build the domestic database ecosystem.

  • DBA Perspective: Dameng’s strategic shift toward all‑in‑one products confirms the trend of domestic databases moving from “software replacement” to “hardware‑software synergy.” The all‑in‑one delivery model lowers the barrier to database deployment and tuning, but also requires DBAs to have a holistic view of hardware‑software synergy. The measured data from Dameng’s previously released DAMENG PAI V2.0 all‑in‑one – I/O latency reduced from 400μs to 80μs – provides a quantifiable reference for selection in core scenarios such as finance and energy.

04|Ningbo Community Health Service Centre Procures Domestic Database: RMB 283,800 Implementation, Medical Xinchuang Continues to Penetrate

On August 11, the Ningbo Haishu District Shiqi Street Community Health Service Centre announced the winning result for its domestic database procurement project, with Ningbo Yirui Information Systems Co., Ltd. winning the bid for RMB 283,800. The procurement covers one batch of domestic database software, using a price inquiry procurement method, with the results announcement period from August 11 to 14.

Following Jieyang Third People’s Hospital’s HRP system procurement of Kingbase (RMB 640,000) and the China Academy of Art’s Xinchuang procurement (RMB 550,000), this represents another grassroots healthcare institution Xinchuang implementation case, reflecting the penetration of domestic databases in the healthcare industry from large tertiary hospitals to community‑level institutions.

  • DBA Perspective: The penetration of medical Xinchuang from tertiary hospitals to grassroots institutions means that the application scenarios for domestic database skills are expanding from “head projects” to “scalable replication.” DBAs should pay attention to the technical requirements of grassroots healthcare Xinchuang projects – unlike the complex HIS/PACS systems of tertiary hospitals, community health service centres have relatively lighter database loads but are numerous, demanding standardised delivery and low‑cost operations.

05|OceanBase Ranks First in China Distributed Database Market: CCID Report Validates Domestic Database Scalability Maturity

CCID Consulting recently released the “2025‑2026 China Platform Software Market Research Annual Report,” showing that China’s platform software market reached RMB 99.13 billion in 2025, up 12.3% year‑on‑year, and is projected to reach RMB 142.03 billion by 2028. In the database sector, OceanBase ranked first in China’s distributed database market, positioned in the “Leader” quadrant of vendor competitiveness assessment and ranking first in product capability.

The report notes that China’s distributed database market is entering the large‑scale application phase, extending from core industries such as finance and telecommunications to government, energy, transportation, and other sectors – becoming the data new infrastructure supporting national livelihoods. OceanBase has served over 400 financial institutions, with nearly 70% of trillion‑yuan banks deploying its systems, and has been ranked first in distributed database financial industry on‑premises deployment for three consecutive years. It also covers one‑third of central SOE core systems, and has been deployed in 22 provinces, municipalities, and autonomous regions in the government sector.

The role of databases is shifting from traditional business system data infrastructure to supporting AI applications – as AI enters production, data types have expanded from traditional structured data to multi‑modal data including documents, images, video, and vectors.

  • DBA Perspective: The CCID report provides industry‑authoritative quantitative references for domestic database selection. Distributed databases entering the “large‑scale application phase” means that in Xinchuang projects across finance, government, energy, transportation, and other industries, leading domestic databases are no longer “pilot options” but mature solutions with large‑scale replacement capabilities. OceanBase’s dual validation across financial core systems and central SOE core systems provides DBAs with a quantifiable evaluation basis for cross‑industry Xinchuang selection.

📚 SQL Little Knowledge Point

This Issue’s Knowledge Point: What is the CISA KEV Catalog?

The CISA KEV (Known Exploited Vulnerabilities Catalog) is a catalog maintained by the U.S. Cybersecurity and Infrastructure Security Agency of security vulnerabilities that have been exploited in the wild with public evidence.

The Role of the KEV Catalog:

  • Mandatory Remediation Timeline: Federal civilian agencies must remediate vulnerabilities in the KEV catalog within specified deadlines (CVE-2026-72898 required completion by August 14).
  • Enterprise Security Benchmark: Although only mandatory for federal agencies, the KEV has become a “priority reference” for enterprise security teams – inclusion in the KEV means the vulnerability has been weaponised and should be prioritised for remediation.

CVE-2026-72898 Key Timeline:

  • August 3: Zero‑day vulnerability exploitation first reported
  • August 10: CVE-2026-72898 formally assigned
  • August 11: CISA adds to KEV, requiring remediation by August 14

Significance for DBAs: The KEV catalog is an authoritative signal for determining whether a vulnerability has been weaponised. When a vulnerability enters the KEV with a “remediation deadline,” DBAs should escalate it from “plan to fix” to “emergency response.”

HiddenMerit Team Production Slogan: 绩优隐于内,金石启新程 | Hidden deep. Merit bold. Forge ahead.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top