• News/
  • bleepingcomputer-20260526084645

CISA orders feds to patch actively exploited Drupal vulnerability

BleepingComputer
·
Sergiu Gatlan
·
Published May 26, 2026
·
Updated

CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. Drupal is typically used by large organizations managing massive data structures and multi-site installations, including government entities, educational organizations, major research universities, and high-profile enterprise and media organizations. Google/Mandiant researcher Michael Maturi discovered this vulnerability (now tracked as CVE-2026-9082) in Drupal's database abstraction API. The security flaw can be exploited without authentication, allowing attackers to trigger arbitrary SQL injection on PostgreSQL-powered sites via specially crafted requests. Successful exploitation can potentially lead to information disclosure, privilege escalation, and even remote code execution. The Drupal security team tagged the flaw as "highly critical" before releasing patches and confirming that exploitation attempts had been detected in the wild. "Since CVE-2026-9082 was released, Imperva has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries," cybersecurity firm Imperva warned on May 21. "Attacks are primarily targeting Gaming and Financial Services sites so far, at collectively almost 50% of all attacks." Internet security watchdog group Shadowserver now tracks nearly 670 unpatched Drupal installations exposed online, most of t...

Read full article

Affected Software

1 affected component
Drupal CMS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA ordering U.S. government agencies to patch a critical SQL injection vulnerability in Drupal that is actively being exploited.

2

What security implications are discussed in the article?

The article highlights the risks associated with an actively exploited vulnerability in Drupal that could lead to unauthorized database access.

3

What products or software are affected?

The affected software mentioned in the article is the Drupal content management system (CMS).

4

What action has CISA required from U.S. government agencies?

CISA has mandated that U.S. government agencies secure their servers against the identified Drupal vulnerability by a specified deadline.

5

What type of vulnerability is being addressed in the article?

The article addresses an SQL injection vulnerability in the Drupal CMS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203