logo

CISA Warns Drupal Core SQL Injection Vulnerability Is Being Exploited in Attacks

ID: 63186a9b-0c2b-5a05-b693-62b789240bd2

STIX ID: report--63186a9b-0c2b-5a05-b693-62b789240bd2

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Divya

...
...

CISA warns of a critical, actively exploited SQL injection in Drupal Core (CVE-2026-9082) that allows unauthenticated attackers to execute malicious queries potentially leading to privilege escalation, data exposure, and remote code execution; the flaw was added to the KEV catalog and organizations are urged to apply patches, harden database access, and update WAF rules immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.