logo

Critical Drupal Core Vulnerability Exposes Websites to Attacks

ID: 9b2353b0-e0a6-58d0-bbec-eb4e25ab8930

STIX ID: report--9b2353b0-e0a6-58d0-bbec-eb4e25ab8930

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Lucas Martin

...
...

The Drupal Security Team released SA-CORE-2026-004 addressing CVE-2026-9082, a highly critical unauthenticated SQL injection in Drupal core's database abstraction API that can allow raw SQL execution against PostgreSQL-backed sites; patches for all supported branches and mitigation guidance are provided and immediate updates are strongly recommended to prevent data disclosure, privilege escalation, or possible remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.