HIGH: Drupal Core SQL Injection CVE-2026-9082 Hits CISA KEV Days After Disclosure
Drupal disclosed SA-CORE-2026-004 (CVE-2026-9082), a Highly Critical SQL injection in the core database abstraction API that lets unauthenticated attackers escalate privileges and reach remote code execution on PostgreSQL-backed sites. Imperva is tracking 15,000+ attack attempts against nearly 6,000 sites across 65 countries. CISA added the bug to KEV on May 22 with a federal patch deadline of May 27, 2026.