Skip to content
CISA Known Exploited Vulnerability

CVE-2026-9082 — Drupal Actively Exploited CVE

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVSS 9.8 ⚠ Actively exploited (CISA KEV) Drupal 2026
CISA catalog entry
Product
Core
Vendor
Drupal
Added to KEV
2026-05-22
Remediation due
2026-05-27