Loading Makriva intelligence feed...
Loading Makriva intelligence feed...
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CISA lists CVE-2026-9082 as known exploited in the wild for Drupal Core. Ransomware campaign use: Unknown. Federal remediation due date: 2026-05-27.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.