CVE-2018-7600General(debian / debian_linux)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • drupal

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 12 mentions across 8 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-10-06); latest day: 3
  • 12 total mentions across 8 days

Affected systems

Products
debian_linuxdrupal

3 versions affected across 2 products

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-03-11: 1Mentions · 2026-04-02: 1Mentions · 2026-04-08: 1Mentions · 2026-08-30: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Mentions · 2026-10-06: 3Mentions · 2026-10-08: 3PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-08-30: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-08-30: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-08-30: 1Technical Details · 2026-03-11: 1Technical Details · 2026-04-02: 103-1104-0204-0808-3009-1309-1410-0610-08
Signal classification3 categories
General
350.0%
Exploit
233.3%
Active Exploitation
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-111
General1
2026-04-021
Exploit1
2026-04-081
Active Exploitation1
2026-08-301
Exploit1
2026-09-131
General1
2026-09-141
General1
Full discourse12 posts
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The text is a historical CVE timeline with no explicit Proof of Concepts, exploit tools, active exploitation claims, named patches, or detailed vulnerability mechanics, serving as a general informational reference.

    31411016411.3K
    3.5K followersView on X
  • Abdulmalik_cybersecurity@malik_cybersec
    Exploit

    Day 28/100 Exploited CVE-2018-7600 (Drupalgeddon2) on Drupal 8 modified a public PoC to upload a PHP webshell, enumerated the filesystem, and read the flag across multiple vhosts. No credentials needed. @commando_skiipz @ce3nerd @KoredeSec @DefendWithFelix @ife0x01 https://t.co/xuKLKziu2y

    Post summary

    The post reports a successful exploitation of CVE-2018-7600 (Drupalgeddon 2) using a modified public PoC, uploading a PHP webshell and enumerating the filesystem across multiple vhosts without credentials.

    1714893.1K
    882 followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet enumerates the top 25 CVEs that have experienced exploitation attempts over a 14‑day period, indicating active exploitation in the wild, but provides no PoC, exploit code, patch information, or technical details.

    070921.2K
    5.5K followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2024-51482 (CVSS: 10) zoneminder CVE-2025-55182 (CVSS: 10) Meta CVE-2026-103956 (CVSS: 10) AWS CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2018-7600 (CVSS: 9.8) n/a ..🧵👇

    110120447
    376 followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-55182 (CVSS: 10) Meta CVE-2026-67401 (CVSS: 9.9) WebPros CVE-2017-5638 (CVSS: 9.8) Apache Softw... CVE-2018-7600 (CVSS: 9.8) n/a CVE-2021-42013 (CVSS: 9.8) Apache Softw... ..🧵👇

    10030208
    375 followersView on X
  • ExploitGrid@exploitgrid

    ├ CVE-2018-7600 · Drupalgeddon2 · PoC live (9.8) └ CVE-2021-42013 · Apache HTTP Server · PoC live (9.8)

    1000038
    375 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2018-7600 [CRITICAL/PoC] CVSS: 9.8 | Vendor: #na DC-1_Vulnhub_Walkthrough 🔗 https://exploitgrid.net/exploits/b78236ee-7bc6-44bf-8d1d-1ece77fa4bf2

    1000048
    375 followersView on X
  • ExploitGrid@exploitgrid

    ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched └ CVE-2018-7600 — Drupalgeddon2 · PoC live, 8 years old and still working

    1000039
    376 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2018-7600 [CRITICAL/PoC] CVSS: 9.8 | Vendor: #na CVE-2018-7600 🔗 https://exploitgrid.net/exploits/638480bf-3fa8-43ba-8666-b45fc7aac554

    1000058
    376 followersView on X
  • ☦︎@ParadoxExe404
    Exploit

    Just rooted my first solo machine. Set up a home hacking lab from scratch on Windows Kali Linux via Docker DC-1 vulnerable VM on VirtualBox Found target with Nmap Exploited Drupalgeddon2 (CVE-2018-7600) via Metasploit Privesc via SUID /usr/bin/find → whoami = root #cybersecurity #pentesting #ethicalhacking #infosec

    Post summary

    The author set up a local lab, discovered a vulnerable VM, exploited Drupalgeddon2 (CVE‑2018‑7600) using Metasploit, and escalated privileges via a SUID binary to gain root.

    0001066
    6 followersView on X
  • chaos@konig0000
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab.

    Post summary

    The text is a generic timeline of historically notable CVEs with a generic call to learn and study patches, containing no actionable exploit, patch, or technical details for any specific vulnerability.

    00000121
    19.8K followersView on X
  • Zzm@Zzmwonw
    General

    🌪️ DRUPALGEDDON 2 — CVE-2018-7600 Zero-auth RCE nuke. One POST = full pwn.Drupal’s Form API blindly trusts array keys starting with # → no proper whitelist.Send a crafted payload to /user/register or /user/password → #CVE #Drupalgeddon #RCE #WebShell #Exploit #Hacking https://t.co/QGVVrT5KDD

    Post summary

    The tweet describes that CVE‑2018‑7600 enables unauthenticated remote code execution by exploiting Drupal’s Form API, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000038
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux7.0--
OSdebiandebian_linux8.0--
OSdebiandebian_linux9.0--
Appdrupaldrupal---

Explore more