đ° Full Story
U.S. cybersecurity agencies and security firms warned this week of active exploitation of a critical SQL injection bug in Drupal Core, tracked as CVE-2026-9082.
Drupal released patches on May 20 and updated its advisory on May 22 to confirm exploit attempts.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal civilian agencies to remediate by May 27, 2026.
Security vendors, including Imperva, reported more than 15,000 attack attempts targeting nearly 6,000 sites across about 65 countries within 48 hours of disclosure; roughly half of observed probes targeted gaming and financial services sites.
The vulnerability affects Drupal sites using PostgreSQL backends (Drupal estimates this is under 5% of installations but still thousands of sites) and can enable information disclosure, privilege escalation and, in some configurations, remote code execution.
Administrators are urged to apply available patches for supported Drupal releases immediately and to investigate suspicious database query activity.







đŹ Commentary