← العودة للجدول
CVE-2026-9082
CVE-2026-9082 — CISA KEV: Drupal Core SQL Injection Vulnerability
📅 2026-05-22
🔴 Critical 🔥 Yes CISA KEV Exploit Web

📋 الوصف الكامل

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

💻 الأنظمة المتأثرة

Drupal Core

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-9082

📡 المصدر

CISA KEV

✅ الحلول والتخفيف

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←