• News/
  • bleepingcomputer-20260522131440

Drupal: Critical SQL injection flaw now targeted in attacks

BleepingComputer
·
Bill Toulas
·
Published May 22, 2026
·
Updated

Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. The content management system (CMS) project published a PSA on May 18, urging administrators to reserve time for core updates that addressed an issue that threat actors might start exploiting "within hours or days." The flaw is now tracked as CVE-2026-9082 and was discovered by Google/Mandiant researcher Michael Maturi. It affects Drupal’s database abstraction API. It allows specially crafted requests to trigger arbitrary SQL injection on sites using PostgreSQL. SQL injection is a flaw in which attackers inject malicious SQL commands into database queries via user input fields or dialogs on websites, resulting in unauthorized access, modification, or deletion of database data. The flaw is exploitable without authentication and could result in remote code execution, privilege escalation, and information disclosure. In an update to the advisory on May 22, Drupal confirmed that exploitation attempts have been detected. “The risk score has been updated to reflect that exploit attempts are now being detected in the wild,” reads the updated advisory. Drupal rated the vulnerability as “highly critical,” assigning it an internal score of 23 out of 25. However, NIST has rated it as “medium severity” based on a CVSS v3 score of 6.5. CVE-2026-9082 impacts a broad range of Drupal versions, including: Website owners and administrators are recommended to up...

Read full article

Affected Software

1 affected component
Drupal Core
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical SQL injection vulnerability in Drupal that is currently being targeted by hackers.

2

What security implications are discussed in the article?

The article highlights the risks associated with a SQL injection vulnerability that could be exploited by attackers to compromise Drupal websites.

3

What version of Drupal is affected by the vulnerability?

The vulnerability affects the core of Drupal, impacting multiple versions of the CMS.

4

What actions should Drupal administrators take in response to this vulnerability?

Administrators are urged to prioritize core updates to address the SQL injection flaw effectively.

5

When was the vulnerability first announced and when did the attacks start?

The vulnerability was announced on May 18, and the attacks targeting it began shortly thereafter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203