Skip to content

CISA Warns Drupal Core SQL Injection Vulnerability Is Being Exploited in Attacks

Gbhackers Divya May 25, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in the wild. The flaw has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling a high risk to organizations using affected Drupal deployments. […]

Extracted Entities

Attack Types (1)

CVEs (1)

CWE Weaknesses (1)

Platforms (1)