Vulnerabilities

Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking

CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.

Vulnerability

Drupal has patched a highly critical vulnerability that could allow threat actors to hack websites powered by the open source content management system (CMS).

The developers of the CMS had alerted users prior to the patch’s release that an exploit might be created within hours or days of disclosure.

The vulnerability, tracked as CVE-2026-9082 and rated ‘highly critical’ with a NIST CMSS score of 20 out of 25, affects an API designed to ensure that database queries are sanitized to prevent SQL injection attacks.

“A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases,” Drupal explains. 

It warns that the flaw can be exploited without authentication to obtain information and in some cases for privilege escalation and remote code execution. 

Drupal powers hundreds of thousands of websites, but CVE-2026-9082 only affects sites that use PostgreSQL. Drupal developers believe less than 5% of websites are impacted.

Advertisement. Scroll to continue reading.

Patches are available for Drupal versions 11.3, 11.2, 10.6, and 10.5.x.

The latest updates also address ‘important’ vulnerabilities in Symfony and Twig that affect Drupal. 

“Depending on your site configuration and contrib modules, you may be vulnerable to one or more of these upstream issues, so updating these dependencies is highly recommended whether the SQL Injection vulnerability affects you or not,” Drupal recommends.

Vulnerabilities are regularly patched in Drupal, but few of them are severe, and there hasn’t been a ‘highly critical’ flaw in years.

There haven’t been any reports of new Drupal flaws being exploited in the wild since 2019. In the years leading up to 2019, several vulnerabilities were exploited, including Drupalgeddon and Drupalgeddon2, which were used to hack many websites.

UPDATE, May 22: Threat actors have started exploiting the vulnerability.

Related: Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Related: Exploitation of Critical NGINX Vulnerability Begins

Related: Anthropic Silently Patches Claude Code Sandbox Bypass

Related Content

Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Vulnerabilities

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.

Vulnerabilities

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.

Vulnerabilities

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

Vulnerabilities

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Vulnerabilities

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

Artificial Intelligence

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version