vulnerability
CISA orders feds to patch actively exploited Drupal vulnerability
Critical
Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system. This vulnerability is actively being exploited, with numerous attacks targeting Drupal sites globally, particularly in the gaming and financial services sectors. The urgency stems from the potential for attackers to gain unauthorized access, escalate privileges, and execute remote code, posing a significant risk to organizations using Drupal.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data