0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Attackers exploit critical Drupal vulnerability affecting PostgreSQL sites (heise.de)

· 65d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Critical SQL injection in Drupal (CVE-2026-9082), PostgreSQL only.
  • Active exploitation without authentication confirmed.
  • Patches for multiple versions, including unsupported branches.
  • Attackers can access data, escalate privileges, or execute code.
  • Patch immediately and upgrade to supported version.

"Attackers are actively exploiting a critical SQL injection vulnerability (CVE-2026-9082) in Drupal CMS that affects only sites using PostgreSQL. The flaw allows unauthenticated attackers to access data, escalate privileges, or execute remote code. Patches have been released for versions 8.9, 9.5, 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10. Administrators are urged to patch immediately."

#Drupal vulnerability #SQL injection #active exploitation

Discussion Matrix

0 segments

no comments yet.