ZeroHour

CVE-2026-9082

KEVmass

Actively Exploited SQL Injection in Drupal Core

CISA: Drupal Core SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2026-9082 is a critical SQL injection flaw (CWE-89) in Drupal core caused by improper neutralization of special elements used in SQL commands, allowing user-controlled input to alter the queries the application executes. The CVSS vector (AV:N/AC:L/PR:N/UI:N) shows it is remotely exploitable over the network without authentication, special privileges, or user interaction. A successful attacker gains high-impact access to the database (read, modify, or disrupt data), and news reports indicate PostgreSQL-backed sites may additionally be exposed to remote code execution. It affects Drupal core from version 8.9.0 onward across all current major lines, with fixes in 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10, meaning essentially all unpatched modern Drupal deployments are at risk. The flaw is confirmed under active attack: CISA added it to the KEV catalog on 2026-05-22 and headlines report it is already being exploited in the wild, while EPSS assigns an 87.9% 30-day exploitation probability (100th percentile); no public proof-of-concept is known yet.

What to do: Upgrade Drupal core immediately to the patched release for your branch: 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, or 11.3.10, or a later release as applicable, since the flaw is being actively exploited and carries an 87.9% EPSS. Prioritize internet-facing sites and deployments using a PostgreSQL database, which reports say can be pushed to remote code execution, and review web and database logs for signs of exploitation. Under the CISA KEV listing (added 2026-05-22), U.S. federal agencies must apply vendor mitigations per applicable BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable.

Affected
Drupal Corefrom 8.9.0 before 10.4.10
Drupal Corefrom 10.5.0 before 10.5.10
Drupal Corefrom 10.6.0 before 10.6.9
Drupal Corefrom 11.0.0 before 11.1.10
Drupal Corefrom 11.2.0 before 11.2.12
Drupal Corefrom 11.3.0 before 11.3.10
Estimated exposure
masslikely hundreds of thousands to 1M+ sites worldwide (all modern Drupal core branches affected) — Estimate based on Drupal's web-wide footprint of roughly 1-2% of all websites per public CMS market-share surveys (on the order of a million or more installations), combined with the fact that the affected ranges span every supported core…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

CISA Known Exploited Vulnerability
Affected
Drupal Core
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
drupal
Products
drupal
Ecosystems
Drupal
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news