CVE-2026-9082
Drupal Core SQL Injection Vulnerability
Description
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal remediation due May 27, 2026 — past due
Advertisement
Coverage
- CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
May 23, 2026
- CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation
May 23, 2026
- CVE-2026-9082: Drupal Under Active Exploitation – Patch Now
May 22, 2026
- CVE-2026-9082: Drupal Core RCE via Database API (PostgreSQL)
May 21, 2026