Skip to content
CISA Known Exploited Vulnerability

CVE-2018-7600

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

⚠ Actively exploited (CISA KEV) Drupal 2018
CISA catalog entry
Product
Drupal Core
Vendor
Drupal
Added to KEV
2021-11-03
Remediation due
2022-05-03

CVE-2018-7600 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.

View CVE-2018-7600 on the NIST National Vulnerability Database →