Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilityrapid-weaponizationend-of-life-software

Drupal Warns of Highly Critical Core Flaw Requiring Immediate Emergency Patching

Updated 20d agoFirst seen May 19, 202625 sources

Drupal has warned administrators to prepare for an emergency core security release affecting all supported branches, saying the undisclosed flaw is highly critical, easy to exploit, and could be weaponized within hours or days of disclosure. According to Drupal and follow-on reporting, the vulnerability requires no privileges and may let attackers expose non-public data or modify or delete site content, although it appears limited to certain uncommon configurations rather than every deployment. A related advisory from dCERT also flagged a Drupal Core vulnerability enabling an unspecified attack.

Security updates are scheduled for supported branches 11.3.x, 11.2.x, 10.6.x, and 10.5.x, with best-effort fixes also planned for older 11.1.x and 10.4.x releases. Sites running 8.9 and 9.5 are expected to receive manual patch files only, with warnings about possible regressions and renewed pressure to upgrade to supported versions such as Drupal 10.6 or later; Drupal 7 is not affected. Drupal Steward customers were said to be protected against known attack vectors, but Drupal still urged all organizations to reserve maintenance time and apply the patch immediately once released.

Share:
Drupal Warns of Highly Critical Core Flaw Requiring Immediate Emergency Patching
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
May 23, 20261mo ago

CISA adds Drupal CVE-2026-9082 to KEV catalog

CISA added the actively exploited Drupal Core SQL injection flaw CVE-2026-9082 to its Known Exploited Vulnerabilities catalog after evidence of in-the-wild abuse. The agency ordered Federal Civilian Executive Branch agencies to remediate by 2026-05-27.

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
May 22, 20261mo ago

Imperva reports 15,000+ attacks on Drupal flaw across 6,000 sites

Imperva said that within 48 hours of Drupal's patch release, it observed more than 15,000 attack attempts exploiting CVE-2026-9082 against nearly 6,000 sites in 65 countries. The activity was largely reconnaissance and validation, with gaming and financial services organizations accounting for almost half of observed attacks.

CVE-2026-9082: Drupal's Highly Critical SQL Injection Flaw Is Already Under Active Attack

Traficom warns Drupal SQL injection flaw is actively exploited

Finland's Traficom warned that the critical Drupal Core SQL injection vulnerability is being actively exploited in the wild, particularly when Drupal uses PostgreSQL as its database. The notice said exploitation can lead to information disclosure and in some cases privilege escalation, arbitrary code execution, and other attacks, while reiterating upgrade guidance for supported and some end-of-life branches.

Drupal Coressa kriittinen ja aktiivisesti hyväksikäytetty SQL-injektion mahdollistava haavoittuvuus | Traficom
May 20, 20261mo ago

Drupal issues SA-CORE-2026-004 for critical SQL injection flaw

Drupal published its May 20, 2026 security advisory SA-CORE-2026-004 addressing a highly critical SQL injection vulnerability in multiple Drupal Core versions. The Canadian Centre for Cyber Security amplified the notice and urged administrators to review the advisory and apply updates or mitigations.

Drupal security advisory (AV26-492) - Canadian Centre for Cyber Security
May 19, 20261mo ago

dCERT publishes advisory on Drupal core vulnerability

Germany's dCERT published Advisory 2026-1550 covering a Drupal Core vulnerability described as allowing an unspecified attack. The advisory reflects external coordination and public notice of the issue ahead of patch release.

Drupal discloses severity and affected version guidance

Alongside the announcement, Drupal said the flaw is highly critical, easy to exploit without privileges, and could expose non-public data or allow modification or deletion of content, though only certain uncommon configurations are affected. It said supported branches 11.3.x, 11.2.x, 10.6.x, and 10.5.x would receive releases, best-effort patches would be provided for 11.1.x, 10.4.x, 9.5, and 8.9, Drupal 7 is unaffected, and older versions should be upgraded.

Drupal announces emergency core security update for May 20

Drupal warned administrators on May 19, 2026 that it would release an emergency core security update on May 20 between 17:00 and 21:00 UTC for supported branches. The project urged site owners to reserve time to apply the fix immediately because exploits could appear within hours or days of disclosure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

22 LINKEDOpen in app
Affected products
6 linked
Drupal CoreDrupalExchange ServerPostgresqlSymfonyMysql
Organizations
14 linked
ImpervaMicrosoft CorporationDrupalSecurity AffairsDrupal StewardTenableCloudflarerunZeroBeazley SecurityThalesCSO OnlineSymfonyTwigDeutsche Telekom Security GmbH
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Drupal Warns of Highly Critical Core Flaw Requiring Immediate Emergency Patching | Mallory