news.mlab.sh
Back to the feed
vulnerability

CISA orders feds to patch actively exploited Drupal vulnerability

Critical
Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system. This vulnerability is actively being exploited, with numerous attacks targeting Drupal sites globally, particularly in the gaming and financial services sectors. The urgency stems from the potential for attackers to gain unauthorized access, escalate privileges, and execute remote code, posing a significant risk to organizations using Drupal.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.