logo

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

ID: f8dae6c2-e1ff-5c0d-b593-2871edeb6c1c

STIX ID: report--f8dae6c2-e1ff-5c0d-b593-2871edeb6c1c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: [email protected] (The Hacker News)

...
...

**CVE-2026-9082 — SQL injection in Drupal Core:** CISA added this recently patched Drupal Core SQL injection (CVSS 6.5) to its KEV after evidence of active exploitation; vendors report more than 15,000 attack attempts against roughly 6,000 sites in 65 countries, largely probing PostgreSQL-backed Drupal sites and focusing on gaming and financial services. Patches are available for supported Drupal versions and FCEB agencies were advised to apply fixes by May 27, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.