VulnerabilitiesMay 22, 2026
RT @CISACyber: 🛡️ We added Drupal core SQL injection vulnerability CVE-2026-9082 to our KEV Cata...
CISA adds Drupal core SQL injection vulnerability CVE-2026-9082 to KEV catalog
Vendor Watch
Run Drupal?
Get an email when a reviewed story names Drupal, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
CISA has added CVE-2026-9082, a SQL injection vulnerability in Drupal core, to its Known Exploited Vulnerabilities (KEV) catalog. The addition indicates this vulnerability is being actively exploited in the wild and organizations should prioritize patching. Administrators running Drupal should apply available security updates immediately.
Indicators of Compromise
- cve — CVE-2026-9082
Entities
Drupal (product)Drupal (vendor)SQL injection (technology)