A critical SQL injection vulnerability, tracked as CVE-2026-9082, has been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog, with a CVSS score of 9.8, indicating a high severity threat1. The flaw affects Drupal Core, specifically sites running PostgreSQL databases, and allows unauthenticated attackers to compromise them. Drupal issued a security patch on May 20 to address this vulnerability, but exploitation attempts began shortly after. The CISA's addition of CVE-2026-9082 to its catalog highlights the urgency of patching this vulnerability, as it is being actively exploited. This vulnerability matters to practitioners because it requires immediate attention and patching to prevent potential site compromises, making it a patch-now situation for organizations using affected Drupal Core versions.
U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog
⚠️ Critical Alert
Why This Matters
CVE-2026-9082 is in active discussion involving CISA — exploitation status determines whether this is patch-now or monitor.
References
- SecurityAffairs. (2026, May 24). U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog. *SecurityAffairs*. https://securityaffairs.com/192566/uncategorized/u-s-cisa-adds-a-flaw-in-drupal-core-to-its-known-exploited-vulnerabilities-catalog.html
Original Source
SecurityAffairs
Read original →