
CISA added an actively exploited Drupal SQL injection to its KEV catalog and gave federal agencies until Wednesday evening to patch. If you're running Drupal in production and haven't patched CVE-2025-50329, you're exposed to trivial database compromise. No auth required. #cybersecurity #infosec https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/
Post summary
CISA added CVE‑2025‑50329, a Drupal SQL injection, to its KEV catalog because it is being actively exploited; agencies must patch by the stated deadline.
