logo

Drupal: Critical SQL injection flaw now targeted in attacks

ID: 5085fb59-0c2f-5b57-8d4a-13f4d43e775c

STIX ID: report--5085fb59-0c2f-5b57-8d4a-13f4d43e775c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Bill Toulas

...
...

Drupal disclosed CVE-2026-9082, a highly critical SQL injection vulnerability in its database abstraction API that allows unauthenticated exploitation on sites using PostgreSQL. Exploit attempts have been observed in the wild; site owners are urged to upgrade affected Drupal branches immediately (multiple 8.x–11.x versions listed) and apply the latest security updates even if not using PostgreSQL due to upstream fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.