AUTO-UPDATED

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical SQL injection vulnerability in Drupal Core to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

Key Points

  • The vulnerability, tracked as CVE-2026-9082, carries a CVSS score of 6.5 and allows for potential privilege escalation and remote code execution.
  • Security firm Imperva reported over 15,000 attack attempts targeting nearly 6,000 websites across 65 countries, primarily in the gaming and financial sectors.
  • Drupal released patches for versions 11, 10, 9.5, and 8.9 to address the flaw within the database abstraction API.
  • Federal Civilian Executive Branch agencies are required to apply the necessary security updates by the May 27, 2026, deadline.

Why it Matters

This vulnerability poses a significant risk because it enables attackers to gain unauthorized access or control over websites running vulnerable PostgreSQL-backed configurations. Organizations using Drupal must prioritize patching immediately to prevent potential data breaches or full system compromise as exploitation attempts continue to rise.
Internet Published by info@thehackernews.com (The Hacker News)
Read original