CISA orders feds to patch actively exploited Drupal vulnerability
ID: bb2e0838-441c-5d2a-9a08-e19b2fe51923
STIX ID: report--bb2e0838-441c-5d2a-9a08-e19b2fe51923
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** CISA has ordered immediate remediation for a highly critical, actively exploited unauthenticated SQL injection vulnerability (CVE-2026-9082) in Drupal's database abstraction API affecting PostgreSQL deployments; Shadowserver reports about 670 unpatched instances and exploitation in the wild, with impacts including data disclosure, privilege escalation, and possible remote code execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
