Skip to content
CISA Known Exploited Vulnerability

CVE-2018-7602

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

⚠ Actively exploited (CISA KEV) Drupal 2018
CISA catalog entry
Product
Core
Vendor
Drupal
Added to KEV
2022-04-13
Remediation due
2022-05-04

CVE-2018-7602 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.

View CVE-2018-7602 on the NIST National Vulnerability Database →