Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
A critical SQL injection vulnerability in Drupal Core is being actively exploited, prompting the CISA to add it to its Known Exploited Vulnerabilities (KEV) catalog. Patches are available for affected versions.
The CISA has added a Drupal Core SQL injection vulnerability (CVE-2026-9082) to its KEV catalog, indicating active exploitation. Drupal has released patches for multiple versions, but Imperva reports over 15,000 attack attempts targeting Drupal sites globally. The vulnerability allows for privilege escalation and remote code execution.
Imagine Drupal is a building with a secret code. This bug lets someone sneak in and change the building's rules, like giving them the key to everything. The CISA found this and told everyone to fix the building's code. Now, bad guys are trying to sneak in, so it's important to update the code quickly. Imperva says they've seen a lot of people trying to sneak in, mostly targeting websites for games and money. The good news is Drupal fixed the problem, but it's still important to update your building's code!
Analysis
The vulnerability, CVE-2026-9082, is an SQL injection flaw within Drupal Core's database abstraction API. According to the CISA, this allows an attacker to inject malicious SQL code, potentially leading to privilege escalation – gaining administrative control – or remote code execution, enabling the attacker to run arbitrary code on the server. The vulnerability was discovered and patched by Drupal, but the fact that it's now being actively exploited underscores the speed at which attackers can identify and leverage weaknesses. Imperva’s observations – over 15,000 attack attempts across nearly 6,000 sites – paint a concerning picture of the scale of the threat. The attacks are primarily targeting gaming and financial services sites, suggesting a targeted approach by attackers. The vulnerability’s nature – allowing for privilege escalation and remote code execution – makes it a high-impact threat. The fact that the activity is dominated by reconnaissance and validation suggests attackers are initially probing for vulnerable systems before attempting to exploit the vulnerability fully. Thales-owned Imperva notes that most observed activity appears to be probing, indicating a cautious approach by attackers before attempting data extraction or privilege escalation. The CISA recommends applying the fixes by May 27, 2026, to mitigate the risk. Drupal released patches for versions 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, 10.4.10, 9.5, and 8.9, with manual patching required for some older versions.
Key points
- CVE-2026-9082 is a critical SQL injection vulnerability in Drupal Core.
- The CISA has added the vulnerability to its KEV catalog, indicating active exploitation.
- Attackers are actively targeting Drupal sites globally.
- The vulnerability allows for privilege escalation and remote code execution.
- Drupal has released patches for multiple versions of the software.



