2026-05-20CRITICALexploitedDrupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC
Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004)
cve · CVE-2026-9082
Coverage
1
first 2026-05-20 → last 2026-05-25
Latest activity
2026-05-23
Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector, education, media · regions: switzerland, europe
Sources cited
13
10 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-9082, newest first. Check the date before acting on an older one.
- Immediate action: Active in-the-wild exploitation was confirmed by Drupal and corroborated by NCSC.ch on 2026-05-22; Imperva reports observing 15,000+ exploitation attempts against ~6,000 sites across 65 countries (Imperva, 2026-05-21). The flaw is an anonymous pre-authentication SQL injection in the Entity Query API's PostgreSQL path, no login, no role, no user interaction required. Swiss federal and cantonal portals, EU institution Drupal instances, and academic SWITCH-hosted sites running PostgreSQL backends are direct targets.2026-05-20CVE-2026-9082
- Patch Drupal CVE-2026-9082 today on every PostgreSQL-backed Drupal deployment, pre-auth SQL injection, active exploitation, 15,000+ attempts measured by Imperva, NCSC.ch status "Actively exploited". Target versions: 10.4.10 / 10.5.10 / 10.6.9 / 11.1.10 / 11.2.12 / 11.3.10 per Drupal SA-CORE-2026-004. MySQL/MariaDB/SQLite backends are unaffected, if patching slips, swap the backend as a temporary control.2026-05-20CVE-2026-9082
Defender insights
What each entry about CVE-2026-9082 tells a defender to do, newest first.
Story timeline
Hunting pivots
Entries about Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004) (1)
Where this entity is cited
Source distribution
- drupal.org4 (31%)
- bleepingcomputer.com1 (8%)
- csoonline.com1 (8%)
- imperva.com1 (8%)
- security-hub.ncsc.admin.ch1 (8%)
- securityweek.com1 (8%)
- slcyber.io1 (8%)
- thehackernews.com1 (8%)
- other2 (15%)
External references
All cited sources (13)
- drupal.orgprimaryDrupal PSA-2026-05-18https://www.drupal.org/psa-2026-05-18
- drupal.orgprimaryDrupal Security Team SA-CORE-2026-004https://www.drupal.org/sa-core-2026-004
- drupal.orgprimaryDrupal Security Advisories feedhttps://www.drupal.org/security
- drupal.orgprimaryDrupal Steward WAFhttps://www.drupal.org/steward
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/drupal-critical-sql-injection-flaw-now-targeted-in-attacks/
- csoonline.comCSO Onlinehttps://www.csoonline.com/article/4175329/drupal-admins-rushing-to-patch-maximum-severity-sql-injection-vulnerability.html
- imperva.comImperva, Customers Protected Against CVE-2026-9082https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-9082-in-drupal-core/
- security-hub.ncsc.admin.chNCSC.ch Security Hub 12584, 2026-05-19https://security-hub.ncsc.admin.ch/#/posts/12584
- securityweek.comSecurityWeek, 2026-05-19https://www.securityweek.com/drupal-to-patch-highly-critical-vulnerability-at-risk-of-quick-exploitation/
- slcyber.ioSearchlight Cyber technical analysishttps://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/
- thehackernews.comThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/drupal-to-release-urgent-core-security.html
- theregister.comThe Register, 2026-05-19https://www.theregister.com/security/2026/05/19/drupal-warns-admins-to-brace-for-highly-critical-core-patch/5242728
- wid.cert-bund.deBSI WID-SEC-2026-1579https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1579