CVE-2026-9082Active Exploitation(drupal / drupal)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 42 mentions and remains active

Immediate actions

  • Patch drupal drupal systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • drupal

Threat summary

  • Active exploitation appears in 88 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 209 mentions across 31 observed days

What's happening

  • Active exploitation reported across 88 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 24 signals
  • Patch or workaround mentioned in 85 signals
  • Technical details provided in 168 signals
  • Disclosure: 42 classified signals
  • Peaked 29d ago at 42 mentions (2026-05-21); latest day: 1
  • 209 total mentions across 31 days

Affected systems

Vendors
Products
drupal

Deep dive

Activity timeline209 mentions / 31d
011213242Mentions · 2026-05-20: 6Mentions · 2026-05-21: 42Mentions · 2026-05-22: 35Mentions · 2026-05-23: 25Mentions · 2026-05-24: 9Mentions · 2026-05-25: 13Mentions · 2026-05-26: 17Mentions · 2026-05-27: 7Mentions · 2026-05-28: 4Mentions · 2026-05-30: 1Mentions · 2026-05-31: 1Mentions · 2026-06-01: 4Mentions · 2026-06-02: 4Mentions · 2026-06-03: 5Mentions · 2026-06-05: 6Mentions · 2026-06-07: 9Mentions · 2026-06-08: 2Mentions · 2026-06-09: 1Mentions · 2026-06-10: 1Mentions · 2026-06-11: 3Mentions · 2026-06-14: 2Mentions · 2026-06-16: 1Mentions · 2026-06-17: 2Mentions · 2026-07-13: 1Mentions · 2026-07-23: 1Mentions · 2026-07-24: 1Mentions · 2026-08-15: 1Mentions · 2026-08-16: 1Mentions · 2026-08-17: 2Mentions · 2026-08-29: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-21: 4PoC Mentioned / Linked · 2026-05-22: 7PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-26: 2PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-05-28: 3PoC Mentioned / Linked · 2026-06-03: 1PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-08-15: 1PoC Mentioned / Linked · 2026-08-17: 1Exploit Tool / Code · 2026-05-21: 1Exploit Tool / Code · 2026-05-22: 3Exploit Tool / Code · 2026-05-25: 1Exploit Tool / Code · 2026-05-26: 2Exploit Tool / Code · 2026-05-28: 1Exploit Tool / Code · 2026-06-17: 1Active Exploitation · 2026-05-21: 6Active Exploitation · 2026-05-22: 15Active Exploitation · 2026-05-23: 18Active Exploitation · 2026-05-24: 5Active Exploitation · 2026-05-25: 9Active Exploitation · 2026-05-26: 12Active Exploitation · 2026-05-27: 2Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-06-01: 3Active Exploitation · 2026-06-02: 2Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-05: 3Active Exploitation · 2026-06-07: 5Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-14: 2Active Exploitation · 2026-07-23: 1Active Exploitation · 2026-08-15: 1Patch / Workaround · 2026-05-20: 5Patch / Workaround · 2026-05-21: 23Patch / Workaround · 2026-05-22: 13Patch / Workaround · 2026-05-23: 9Patch / Workaround · 2026-05-24: 5Patch / Workaround · 2026-05-25: 4Patch / Workaround · 2026-05-26: 8Patch / Workaround · 2026-05-27: 4Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-02: 3Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-05: 4Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-05-20: 5Technical Details · 2026-05-21: 37Technical Details · 2026-05-22: 24Technical Details · 2026-05-23: 23Technical Details · 2026-05-24: 7Technical Details · 2026-05-25: 12Technical Details · 2026-05-26: 13Technical Details · 2026-05-27: 7Technical Details · 2026-05-28: 3Technical Details · 2026-05-30: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-01: 4Technical Details · 2026-06-02: 4Technical Details · 2026-06-03: 5Technical Details · 2026-06-05: 4Technical Details · 2026-06-07: 6Technical Details · 2026-06-10: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-17: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-24: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-29: 1Technical Details · 2026-09-11: 105-2005-2305-2605-3006-0206-0706-1006-1607-2308-1609-11
Signal classification7 categories
Active Exploitation
8540.7%
Disclosure
4220.1%
Patch
3918.7%
General
2712.9%
PoC
136.2%
Exploit
21.0%
Referenced assets153 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-206
General1Patch5
2026-05-2142
Active Exploitation6Disclosure14General3Patch16PoC3
2026-05-2235
Active Exploitation15Disclosure7General4Patch5PoC4
2026-05-2325
Active Exploitation18Disclosure3False Positive1General2Patch1
2026-05-249
Active Exploitation5Disclosure1General1Patch1PoC1
2026-05-2513
Active Exploitation8Disclosure2General1Patch2
2026-05-2617
Active Exploitation11Disclosure2General1Patch2PoC1
2026-05-277
Active Exploitation2Disclosure2General2Patch1
2026-05-284
Disclosure1Exploit1Patch1PoC1
2026-05-301
Patch1
2026-05-311
Disclosure1
2026-06-014
Active Exploitation3General1
2026-06-024
Active Exploitation2Disclosure1Patch1
2026-06-035
Active Exploitation1Disclosure2General1PoC1
2026-06-056
Active Exploitation3Disclosure1Exploit1Patch1
2026-06-079
Active Exploitation5Disclosure4
2026-06-082
Active Exploitation1Patch1
2026-06-091
General1
2026-06-101
General1
2026-06-113
Active Exploitation1Disclosure1General1
2026-06-142
Active Exploitation2
2026-06-161
General1
2026-06-172
General1PoC1
2026-07-131
General1
2026-07-231
Active Exploitation1
2026-07-241
General1
2026-08-151
Active Exploitation1
2026-08-161
Patch1
2026-08-172
General1PoC1
2026-08-291
General1
2026-09-111
General1
Full discourse20 posts
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Patch

    CVE-2026-9082 Drupal core SQL injection https://www.drupal.org/sa-core-2026-004 https://t.co/DKlMy016cM

    Post summary

    The tweet references Drupal core CVE‑2026‑9082 as an SQL injection flaw and links to a Drupal security advisory that presumably contains a patch and mitigation steps; no active exploitation or exploit code is mentioned.

    070041817629.2K
    81.6K followersView on X
  • International Cyber Digest@IntCyberDigest
    Patch

    ‼️🚨 Drupal CMS (which powers about 1 in 100 websites on the internet) has just released, not a 'critical' vuln patch, but a 'highly critical' patch to fix a SQL injection vuln. This vulnerability only affects sites using PostgreSQL. ID: CVE-2026-9082 https://t.co/0uXabu2jOw

    Post summary

    Drupal CMS has released a highly critical patch to address a SQL injection vulnerability (CVE-2026-9082) that affects PostgreSQL-powered sites.

    76262827439.6K
    193.5K followersView on X
  • shubs@infosec_au
    General

    We recently analyzed Drupal's security advisory (SA-CORE-2026-004 & CVE-2026-9082). This pre-auth SQLi only affects Drupal with Postgres as a db backend. Our research team at @SLCyberSec have published a writeup here: https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/

    Post summary

    The post discusses an analysis of Drupal’s CVE‑2026‑9082 – a pre‑authentication SQL injection limited to Postgres – and provides a link to a detailed write‑up, but it does not supply PoC code, exploits, active‑use reports, or patch information.

    22421295410.6K
    58.8K followersView on X
  • Ambionics Security@ambionics
    Exploit

    🔓 On an asset under our continuous monitoring, our pentester @nol_tech turned a SELECT-only PostgreSQL SQLi in Drupal (CVE-2026-9082) into a full RCE when DB role is superuser. Details below 👇 📝 https://blog.lexfo.fr/drupal-postgresql-sqli-to-rce.html 🛠️ https://github.com/ambionics/cve-2026-9082-drupal-postgresql-rce #Drupal #PostgreSQL #RCE #SQLi

    Post summary

    The tweet announces a pentester’s proof‑of‑concept that turns CVE‑2026‑9082 into a full RCE, with code shared via GitHub, but does not report any active exploitation or patch availability.

    220267299.0K
    2.0K followersView on X
  • Patrik Grobshäuser@ITSecurityguard
    Disclosure

    Our team at @SLCyberSec / @assetnote just shipped a same-day breakdown of CVE-2026-9082: critical anonymous SQLi in Drupal core, no auth needed. 👀 lots of bug bounty targets in scope. Technical details 👇 https://t.co/Y9fp5bOHD3

    Post summary

    The post announces a detailed breakdown of CVE-2026-9082, a critical anonymous SQL injection in Drupal core that requires no authentication, and provides a link for further technical details.

    212073334.9K
    31.7K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Drupal Core SQL injection is now actively exploited. https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html CISA added CVE-2026-9082 to its KEV catalog after exploitation was detected in the wild. Imperva observed: • 15,000+ attack attempts • Nearly 6,000 targeted sites • Activity across 65 countries • Gaming and financial services sites hit hardest, at nearly 50% of attacks The flaw affects all supported Drupal Core versions and could allow privilege escalation and remote code execution via specially crafted requests. Patch now: • Drupal 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, 10.4.10. • Drupal 9.5 and 8.9 require manual patching.

    Post summary

    The post reports that Drupal Core’s SQL injection flaw (CVE-2026-9082) is actively exploited worldwide, provides exploitation statistics, and offers patch information.

    321270613.4K
    1.9M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Drupal core SQL injection vulnerability CVE-2026-9082 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/eRicxXzjb3

    Post summary

    The tweet announces that the Drupal core SQL injection vulnerability CVE-2026-9082 has been added to DHS’s KEV catalog, signifying it has been exploited in the wild, but offers no PoC, exploit code, or patch details.

    41324228.1K
    300.1K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Drupal CVE-2026-9082 boolean-blind extractor https://gist.github.com/dinosn/65a7da94cd93e0699f0549c70095eba2 , as per http://slcyber.io https://t.co/M9MXp2Yjn5

    Post summary

    The post reveals a proof‑of‑concept script for the Drupal CVE‑2026‑9082 Boolean blind vulnerability, linking to the code but providing no evidence of active exploitation or a patch.

    06035224.5K
    158.6K followersView on X
  • Densel@luckyhacker43
    PoC

    Drupal CVE-2026-9082 Blind SQL Injection Checker 👾💉 🔗 https://github.com/N45HT/drupal-cve-2026-9082-checker 🔗 https://www.cve.org/CVERecord?id=CVE-2026-9082 🔗 https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/ https://t.co/LmkkKg4bpI

    Post summary

    The post announces a GitHub-based checker for Drupal CVE-2026-9082 Blind SQL Injection, providing a PoC but offering no patches, exploitation details, or confirmation of active attacks.

    27029221.2K
    3.6K followersView on X
  • Sekurak@Sekurak
    Patch

    Masz Drupala? To łataj się jak najszybciej. ❌ Krytyczna podatność CVE-2026-9082 to SQL injection, który może być zrealizowany na ekranie logowania (czyli bez posiadania konta...) ❌ Działa to jeśli używasz bazy PostgreSQL ❌ Działa w standardowej konfiguracji Drupal 9 oraz 10, ale producent przygotował łatki dla w zasadzie wszystkich wersji (łącznie z tymi, które są już teoretycznie niewspierane - czyli 8.x oraz 9.x) ❌ Dostępny jest już exploit, więc warto się pospieszyć

    Post summary

    CVE‑2026‑9082 is a critical PostgreSQL‑based SQL injection in Drupal 9/10; an exploit exists and vendors have released patches for all supported versions.

    0403985.7K
    43.9K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    Drupalで公開された重大SQLインジェクション脆弱性「CVE-2026-9082」が、修正公開直後から大規模に悪用され始めた。既に48時間で1万5000件超の攻撃が確認されている。 問題はPostgreSQLを利用するDrupal環境に影響する。データベースクエリを安全化するAPIに欠陥があり、攻撃者は細工したリクエストで任意SQLを実行できる。認証不要で悪用可能で、情報窃取、権限昇格、条件次第ではリモートコード実行にも発展する恐れがある。 Drupalは5月20日に修正版を公開し、数時間から数日以内に攻撃が始まる可能性を警告していた。実際、5月22日には「既に実環境で悪用試行を確認している」とアドバイザリを更新した。Drupal独自CVSSでは23点となり、最高25点中の極めて深刻な評価を受けている。 Impervaによれば、公開後2日間で約6000サイトを狙う1万5000件超の攻撃を観測した。標的は65カ国に及び、特にゲーム業界と金融業界が全体の約半数を占める。現在は脆弱サイト探索や検証段階が中心だが、今後はデータ窃取や権限奪取へ移行する可能性が高いという。 https://securityaffairs.com/192557/security/cve-2026-9082-drupals-highly-critical-sql-injection-flaw-is-already-under-active-attack.html

    Post summary

    CVE‑2026‑9082, a highly critical SQL injection in Drupal, was patched on May 20 but has already been widely exploited, with over 15,000 attacks detected worldwide in just 48 hours.

    05031103.8K
    14.5K followersView on X
  • Swissky@pentest_swissky
    General

    Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) - Patrik Grobshäuser, Kevin Gervot, Tomais Williamson - @SLCyberSec https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/

    Post summary

    The post references a newly disclosed anonymous SQL injection in Drupal Core (CVE‑2026‑9082) with no details on exploits, patches, or active use.

    08022152.3K
    22.5K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - 7h30th3r0n3/CVE-2026-9082-Drupal-PoC: Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites. · GitHub https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC

    Post summary

    The GitHub repository provides an ethical Proof of Concept demonstrating anonymous SQL injection in Drupal via the JSON:API module on PostgreSQL sites.

    05018121.8K
    62.5K followersView on X
  • Defused@DefusedCyber
    General

    ⚠️ We are observing actors sending test exploits against the recent Drupal vulnerability CVE-2026-9082 since this morning Probes hit /jsonapi/node/* with a malformed filter[…][value][…] key, triggering the SQL injection bug to check whether the site is vulnerable. No data-extraction payloads yet, so this is likely recon ahead of the real wave. Monitor live attacks against Drupal 👉https://console.defusedcyber.com/intel

    Post summary

    The post reports early recon probing against Drupal CVE‑2026‑9082 via malformed JSONAPI filters that trigger an SQL injection, with no exploitation yet observed.

    0711945.7K
    7.5K followersView on X
  • watchTowr@watchtowrcyber
    General

    Rapid reaction gets you ahead. 2 days before CISA added CVE-2026-9082 a critical SQL Injection vulnerability in Drupal Core, to KEV, watchTowr clients were aware of their exposure. Reach out via our website if you need support. https://t.co/9yEKZfcyz2

    Post summary

    The tweet notes that watchTowr clients were aware of the Drupal Core SQL injection vulnerability before CISA added it to KEV, but provides no PoC, exploit, or patch details.

    0501933.0K
    12.6K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/22追加) 🛡️No.1603 CVE-2026-9082 Drupal Core SQL Injection Vulnerability ================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Drupal .org (CNA) ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Drupal core のデータベース抽象化 API に存在する SQL インジェクションの脆弱性が存在します。PostgreSQL を使用しているサイトでは、細工されたリクエストにより任意の SQL インジェクションを実行される恐れがあります。 Drupal は、匿名ユーザーでも悪用可能であり、情報漏えいに加えて、場合によっては権限昇格、リモートコード実行、その他の攻撃につながる可能性があると説明。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Drupal core が稼働していること。 ・サイトが PostgreSQL データベースを使用していること。 ・攻撃者が対象サイトへネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・任意の SQL インジェクションを実行される ・情報漏えいにつながる ・場合によっては権限昇格、リモートコード実行、その他の攻撃につながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Drupal は 2026年5月22日に、悪用の試行が実環境で検知されていることを理由にリスクスコアを更新したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-9082 https://www.drupal.org/sa-core-2026-004 https://www.tenable.com/blog/cve-2026-9082-highly-critical-sql-injection-vulnerability-in-drupal-core-sa-core-2026-004 https://github.com/ywh-jfellus/CVE-2026-9082 https://www.cisa.gov/news-events/alerts/2026/05/22/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA has added CVE‑2026‑9082 to the KEV catalog after confirmed in‑the‑wild exploitation, with publicly available PoC code and a vendor patch already issued.

    0301346.6K
    43.9K followersView on X
  • SecurityWeek@SecurityWeek
    General

    Drupal Vulnerability CVE-2026-9082 in Hacker Crosshairs Shortly After Disclosure https://www.securityweek.com/drupal-vulnerability-in-hacker-crosshairs-shortly-after-disclosure/

    Post summary

    The snippet only indicates a newly disclosed Drupal CVE without providing additional details on exploitation, patching, or technical characteristics.

    0821003.8K
    228.2K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    👉 Vous utilisez le CMS Drupal pour votre site Web ? Patchez : il y a une belle injection SQL... ✍️ Plus d'infos par ici : https://www.it-connect.fr/drupal-cve-2026-9082-cette-faille-critique-de-type-injection-sql-menace-les-sites-web/ #CMS #Drupal https://www.it-connect.fr/drupal-cve-2026-9082-cette-faille-critique-de-type-injection-sql-menace-les-sites-web/

    Post summary

    The tweet highlights a new Drupal vulnerability (CVE‑2026‑9082) that introduces an SQL injection flaw and urges users to apply a patch.

    060122926
    11.5K followersView on X
  • Horizon3.ai@Horizon3ai
    PoC

    🚨 A public-facing Drupal site backed by PostgreSQL should be treated as high risk right now. We reversed CVE-2026-9082 and released a Rapid Response test. https://t.co/FdcbAaBigV

    Post summary

    The mention focuses on a released Rapid Response test for CVE‑2026‑9082, indicating a proof‑of‑concept was provided, but no active exploitation or patch details are included.

    16061438
    2.9K followersView on X
  • Nicolas Krassas@Dinosn
    General

    CVE-2026-9082 Drupal Core PostgreSQL SQL Injection Overview and Takeaways https://www.netspi.com/blog/executive-blog/critical-vulnerability/cve-2026-9082-drupal-core-postgresql-sql-injection-overview-and-takeaways/

    Post summary

    The excerpt points to a blog article discussing CVE‑2026‑9082 as a SQL injection flaw in Drupal Core’s PostgreSQL handling, but it does not provide PoC details, exploit code, active exploitation evidence, or mitigation information.

    010931.3K
    158.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdrupaldrupal---

Explore more