CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004)

cve · CVE-2026-9082

Coverage
1
first 2026-05-20 → last 2026-05-25
Latest activity
2026-05-23
Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector, education, media · regions: switzerland, europe
Sources cited
13
10 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-9082, newest first. Check the date before acting on an older one.

  • Immediate action: Active in-the-wild exploitation was confirmed by Drupal and corroborated by NCSC.ch on 2026-05-22; Imperva reports observing 15,000+ exploitation attempts against ~6,000 sites across 65 countries (Imperva, 2026-05-21). The flaw is an anonymous pre-authentication SQL injection in the Entity Query API's PostgreSQL path, no login, no role, no user interaction required. Swiss federal and cantonal portals, EU institution Drupal instances, and academic SWITCH-hosted sites running PostgreSQL backends are direct targets.
    2026-05-20CVE-2026-9082
  • Patch Drupal CVE-2026-9082 today on every PostgreSQL-backed Drupal deployment, pre-auth SQL injection, active exploitation, 15,000+ attempts measured by Imperva, NCSC.ch status "Actively exploited". Target versions: 10.4.10 / 10.5.10 / 10.6.9 / 11.1.10 / 11.2.12 / 11.3.10 per Drupal SA-CORE-2026-004. MySQL/MariaDB/SQLite backends are unaffected, if patching slips, swap the backend as a temporary control.
    2026-05-20CVE-2026-9082

Defender insights

What each entry about CVE-2026-9082 tells a defender to do, newest first.

2026-05-20CRITICALexploitedDrupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC

Story timeline

  1. 2026-05-20Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC
    active-threats

Entries about Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004) (1)

2026-05-20 · view entry permalink →

CRITICALCVE-2026-9082exploitedupdated

Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC

On 2026-05-18 the Drupal Security Team published PSA-2026-05-18 reserving an emergency out-of-band release for today, 2026-05-20, 17:00–21:00 UTC. The pre-advisory scores the flaw 20/25 on Drupal's own published security scale (the second-highest tier) with Access Complexity "None" and Authentication "None", meaning exploitation is unauthenticated and requires no special conditions; the chained score sits below the theoretical 25/25 only because the Drupal Security Team rates the affected configuration as "Uncommon". CVE assignment and class are embargoed until release. Affected branches: 10.5.x, 10.6.x, 11.2.x, 11.3.x receive official patches; Drupal also reserved manual emergency patch files for EOL branches 8.9, 9.5, 10.4 (→ 10.4.9) and 11.1 (→ 11.1.9), an unusual step that itself signals severity. Drupal 7 is not affected. The Security Team explicitly notes "exploits might be developed within hours or days". NCSC.ch's Security Hub corroborates the urgency, reiterating that "Successful exploitation could allow unauthenticated attackers to fully compromise affected Drupal installations". BSI WID-SEC-2026-1579 carries the same advance warning (BSI CERT-Bund).

Why it matters to us: Drupal is the dominant CMS for Swiss federal / cantonal / municipal portals, European Commission and EU-agency sites, universities, and public-sector NGOs. No technical mitigation exists pre-patch. Schedule the patch window now and monitor the Drupal Security Advisories feed for the CVE and patch links the moment they publish at 17:00 UTC.

Drupal confirmed: exploit attempts are now being detected in the wild

BleepingComputer

Current exploitation status: Actively exploited

NCSC.ch Security Hub

Imperva sees more than 15,000 exploit attempts against around 6,000 Drupal websites in 65 countries

Imperva
Updaterun 2026-05-21-77cdc4cdcvesprioritysectorssourcestagsbody

Yesterday's brief carried Drupal's PSA pre-warning that a "highly critical" core advisory was scheduled for 2026-05-20; today the SA-CORE-2026-004 advisory landed with CVE-2026-9082 assigned, an anonymous SQL-injection in Drupal core's database abstraction API (CWE-89) rated 20/25 on Drupal's risk scale (Highly Critical) that affects only PostgreSQL-backed installations. Specially-crafted HTTP requests slip past sanitisation in the core DB-API layer and inject arbitrary SQL with no authentication; successful exploitation leads to information disclosure, privilege escalation and (in some database configurations) RCE. The Drupal Security Team explicitly stated that "exploits might be developed within hours or days" of advisory release (Drupal PSA, 2026-05-18).

Affected versions: 8.9.0 through 10.4.10, 10.5.x < 10.5.10, 10.6.x < 10.6.9, 11.0.0 through 11.1.10, 11.2.x < 11.2.12, 11.3.x < 11.3.10. Patched: 10.4.10 / 10.5.10 / 10.6.9 / 11.1.10 / 11.2.12 / 11.3.10 (released 2026-05-20). MySQL / MariaDB / SQLite installations are not affected by this CVE. Drupal 7 is unaffected; sites on EOL Drupal 8/9 majors must apply manual patch files. Drupal Steward WAF subscribers receive vendor-provided rules at advisory release per the service description; non-subscriber sites must apply the core update. NCSC-CH carried the advisory in its Security Hub (NCSC-CH, 2026-05-19; SecurityWeek, 2026-05-19; CSO Online, 2026-05-20).

Updaterun 2026-05-23-852c21c8actionscvesevidenceimmediate_actionprioritysourcestagsbody

On 2026-05-22 Drupal updated SA-CORE-2026-004 to confirm that exploit attempts targeting CVE-2026-9082 (the anonymous pre-authentication SQL injection in the Entity Query API's PostgreSQL path) are now being detected in the wild. NCSC.ch updated Security Hub post 12584 to "Actively exploited" status the same day at 13:52Z, also recording the addition of CVE-2026-9082 to the CISA Known Exploited Vulnerabilities catalog on 2026-05-22 (the NCSC-CH post is the brief's source of record on the KEV add; the CISA news-events alert URL constructed earlier in the day returned a 404 at composition time).

Imperva reports observing 15,000+ exploitation attempts against approximately 6,000 Drupal sites across 65 countries within days of disclosure (Imperva, 2026-05-21). The technical mechanism (now public via the Searchlight Cyber write-up): on the case-insensitive IN operator path through core/lib/Drupal/Core/Entity/Query/Sql/Condition::compile() / ConditionAggregate::compile(), a JSON-encoded array value survives into the SQL placeholder name without sanitisation, allowing injection when the backend is PostgreSQL. Fixed versions: 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12 and 11.3.10; best-effort patches for EOL Drupal 8.9 and 9 are also available. MySQL/MariaDB/SQLite-backed Drupal sites remain unaffected, which is the temporary control to fall back on if the patch window slips past today.

Defender vantage update from yesterday's brief: the operational frame is no longer "patch when convenient" but patch today; the § 0 Immediate Action carries the operational framing; this UPDATE captures the source-of-record links and the technical mechanism for anyone composing internal advisories or hunt queries. CH/EU specifics: NCSC.ch Security Hub is the authoritative jurisdictional source for Swiss federal and cantonal operators; Drupal-on-PostgreSQL is widespread across FITKO and SWITCH-hosted university sites, French gouvernement.fr instances and EU institution portals. Detection: WAF telemetry for nested JSON arrays in user-supplied fields hitting Drupal endpoints; PostgreSQL log_min_duration_statement to surface anomalous query shapes; web-server logs for unexpected POST payloads to anonymous routes.

threat20 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • drupal.org4 (31%)
  • bleepingcomputer.com1 (8%)
  • csoonline.com1 (8%)
  • imperva.com1 (8%)
  • security-hub.ncsc.admin.ch1 (8%)
  • securityweek.com1 (8%)
  • slcyber.io1 (8%)
  • thehackernews.com1 (8%)
  • other2 (15%)

External references

NVD · cve.org · CISA KEV

All cited sources (13)