CISA Known Exploited Vulnerability
CVE-2026-9082 — Drupal Actively Exploited CVE
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CISA catalog entry
Product
Core
Vendor
Drupal
Added to KEV
2026-05-22
Remediation due
2026-05-27
What WebPulse reported · 2 analyses
Drupal Was the Safe One. Then CVE-2026-9082 Hit CISA KEV.
CVSS 9.8. Unauthenticated SQL injection in Drupal Core. Added to CISA KEV two days after disclosure. 15,000 attacks across 65 countries. The CMS governments cho
June 9, 2026
CISA BOD 26-04 Replaces BOD 19-02: 3 Days to Patch Critical Vulnerabilities
Binding Operational Directive 26-04 replaces the old 30-day patch window with risk-based timelines. Publicly exposed, auto-exploitable vulnerabilities in the KE
June 16, 2026
Related vulnerabilities