high
CISA KEV
CVE-2026-9082
Drupal Core SQL Injection Vulnerability
// Description
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
// Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal remediation due May 27, 2026 — past due
Advertisement
// Coverage
- CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
May 23, 2026
- CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation
May 23, 2026
- CVE-2026-9082: Drupal Under Active Exploitation – Patch Now
May 22, 2026
- CVE-2026-9082: Drupal Core RCE via Database API (PostgreSQL)
May 21, 2026