Drupal Core SQL Injection Active Exploitation | MSSP Advisory
Critical
DateMay 23, 2026
📋Executive Summary
CISA added CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. The flaw affects all supported versions of Drupal Core with a CVSS score of 6.5. Attackers can manipulate database queries to extract sensitive data or gain unauthorized access to Drupal installations.
⚠️Why It Matters for MSSPs
Your RMM or PSA dashboards running on Drupal are direct targets for credential theft and lateral movement into client networks. Every client website, portal, or internal system running Drupal gives attackers a foothold to steal data or deploy ransomware, and CISA adding this to KEV means exploitation is happening right now.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.