CVE-2026-9082: Drupal Core SQL Injection Vulnerability. Drupal Core
Drupal Core SQL Injection Vulnerability. Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
- CISA KEV-listed (remediation due 2026-05-27)
- EPSS 10.4% (93.4% percentile)