Skip to content
CISA Known Exploited Vulnerability

CVE-2026-9082 — Drupal, Joomla Actively Exploited CVE

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVSS 9.8 ⚠ Actively exploited (CISA KEV) Drupal Joomla 2026
CISA catalog entry
Product
Core
Vendor
Drupal
Added to KEV
2026-05-22
Remediation due
2026-05-27
What WebPulse reported · 6 analyses
Drupal Was the Safe One. Then CVE-2026-9082 Hit CISA KEV.

CVSS 9.8. Unauthenticated SQL injection in Drupal Core. Added to CISA KEV two days after disclosure. 15,000 attacks across 65 countries. The CMS governments cho

June 9, 2026
Drupal Has 5 CISA KEV Entries. The Enterprise CMS Is on the Federal Watchlist.

Drupal has more KEV entries than any CMS. The latest PostgreSQL RCE was added May 2026.

June 21, 2026
Joomla JCE Scores a Perfect 10: CISA KEV, PHP Web Shells, Zero Authentication Required

CVE-2026-48907 is a CVSS 10.0 flaw in the Joomla Content Editor plugin. Attackers upload PHP web shells through unauthenticated profile imports. CISA orders fed

June 18, 2026
CISA BOD 26-04 Replaces BOD 19-02: 3 Days to Patch Critical Vulnerabilities

Binding Operational Directive 26-04 replaces the old 30-day patch window with risk-based timelines. Publicly exposed, auto-exploitable vulnerabilities in the KE

June 16, 2026
TYPO3: Another Legacy CMS, Another Form Framework SQL Injection, Another Privilege Escalation

TYPO3-CORE-SA-2026-019. Broken access control in the Form Framework allows maliciously crafted form definitions to execute arbitrary SQL and create admin accoun

June 13, 2026
Drupal Core SQL Injection: Anonymous Access, CISA KEV, Exploited in the Wild

CVE-2026-9082. Highly critical. Anonymous SQL injection in Drupal core — not a contributed module, not a plugin, the core framework itself. CISA added it to the

June 13, 2026
View CVE-2026-9082 on the NIST National Vulnerability Database →