The U.S. Cybersecurity and Infrastructure Security Agency has added a critical SQL injection vulnerability in Drupal Core to its Known Exploited Vulnerabilities catalog following reports of active exploitation.
Key Points
- The vulnerability, tracked as CVE-2026-9082, carries a CVSS score of 6.5 and allows for potential privilege escalation and remote code execution.
- Security firm Imperva reported over 15,000 attack attempts targeting nearly 6,000 websites across 65 countries, primarily in the gaming and financial sectors.
- Drupal released patches for versions 11, 10, 9.5, and 8.9 to address the flaw within the database abstraction API.
- Federal Civilian Executive Branch agencies are required to apply the necessary security updates by the May 27, 2026, deadline.