logo

CISA orders feds to patch actively exploited Drupal vulnerability

ID: bb2e0838-441c-5d2a-9a08-e19b2fe51923

STIX ID: report--bb2e0838-441c-5d2a-9a08-e19b2fe51923

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Sergiu Gatlan

...
...

**Executive summary:** CISA has ordered immediate remediation for a highly critical, actively exploited unauthenticated SQL injection vulnerability (CVE-2026-9082) in Drupal's database abstraction API affecting PostgreSQL deployments; Shadowserver reports about 670 unpatched instances and exploitation in the wild, with impacts including data disclosure, privilege escalation, and possible remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.