CVE-2026-9082: Drupal's Highly Critical SQL Injection Flaw Is Already Under Active AttackSecurity Affairs·May 23, 16:17 UTC · May 23, 2026Vulnerability in the wildCVE-2026-908260
U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 24, 07:54 UTC · May 24, 2026Exploit / PoC in the wildCVE-2026-908260
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE AttacksThe Hacker News·May 22, 05:30 UTC · May 22, 2026VulnerabilityCVE-2026-908260
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEVThe Hacker News·May 23, 13:25 UTC · May 23, 2026Exploit / PoC in the wildCVE-2026-908260