discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

A critical SQL injection vulnerability in Drupal Core is being actively exploited, prompting the CISA to add it to its Known Exploited Vulnerabilities (KEV) catalog. Patches are available for affected versions.

By Ravie Lakshmanan·May 23·thehackernews.com·2 min read

The CISA has added a Drupal Core SQL injection vulnerability (CVE-2026-9082) to its KEV catalog, indicating active exploitation. Drupal has released patches for multiple versions, but Imperva reports over 15,000 attack attempts targeting Drupal sites globally. The vulnerability allows for privilege escalation and remote code execution.

Why it matters

This vulnerability highlights the ongoing risk of SQL injection attacks against widely used content management systems like Drupal, emphasizing the importance of timely patching and security monitoring.

Imagine Drupal is a building with a secret code. This bug lets someone sneak in and change the building's rules, like giving them the key to everything. The CISA found this and told everyone to fix the building's code. Now, bad guys are trying to sneak in, so it's important to update the code quickly. Imperva says they've seen a lot of people trying to sneak in, mostly targeting websites for games and money. The good news is Drupal fixed the problem, but it's still important to update your building's code!

Analysis

The vulnerability, CVE-2026-9082, is an SQL injection flaw within Drupal Core's database abstraction API. According to the CISA, this allows an attacker to inject malicious SQL code, potentially leading to privilege escalation – gaining administrative control – or remote code execution, enabling the attacker to run arbitrary code on the server. The vulnerability was discovered and patched by Drupal, but the fact that it's now being actively exploited underscores the speed at which attackers can identify and leverage weaknesses. Imperva’s observations – over 15,000 attack attempts across nearly 6,000 sites – paint a concerning picture of the scale of the threat. The attacks are primarily targeting gaming and financial services sites, suggesting a targeted approach by attackers. The vulnerability’s nature – allowing for privilege escalation and remote code execution – makes it a high-impact threat. The fact that the activity is dominated by reconnaissance and validation suggests attackers are initially probing for vulnerable systems before attempting to exploit the vulnerability fully. Thales-owned Imperva notes that most observed activity appears to be probing, indicating a cautious approach by attackers before attempting data extraction or privilege escalation. The CISA recommends applying the fixes by May 27, 2026, to mitigate the risk. Drupal released patches for versions 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, 10.4.10, 9.5, and 8.9, with manual patching required for some older versions.

Key points

  • CVE-2026-9082 is a critical SQL injection vulnerability in Drupal Core.
  • The CISA has added the vulnerability to its KEV catalog, indicating active exploitation.
  • Attackers are actively targeting Drupal sites globally.
  • The vulnerability allows for privilege escalation and remote code execution.
  • Drupal has released patches for multiple versions of the software.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritydrupalsql injectioncisaimpervavulnerabilityexploitation

Author

Ravie Lakshmanan

Published

May 23, 2026

Source

thehackernews.com

Share

Topics

securitydrupalsql injectioncisaimpervavulnerabilityexploitation

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…