vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system. This vulnerability is actively being exploited, with numerous attacks targeting Drupal sites globall… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
vulnerability Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active… The Hacker News · May 23, 2026 Critical CVE-2026-9082
vulnerability Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Dis… SecurityWeek · May 22, 2026 Medium CVE-2026-9082
vulnerability Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. BleepingComputer · May 22, 2026 Medium CVE-2026-9082
vulnerability Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appear… SecurityWeek · May 21, 2026 Critical CVE-2026-9082
vulnerability Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. T… The Hacker News · May 21, 2026 High CVE-2026-9082