HIGH: Drupal Core SQL Injection Hits CISA KEV as Imperva Logs 15,000 Attacks
CVE-2026-9082, a SQL injection flaw in Drupal core database abstraction API, was added to the CISA Known Exploited Vulnerabilities catalog on May 22, 2026, less than 48 hours after patches were released. Imperva has logged over 15,000 attack attempts against roughly 6,000 sites across 65 countries, with PostgreSQL-backed gaming and financial services sites bearing the brunt. The bug enables privilege escalation and remote code execution.