A critical vulnerability in Drupal core, identified as CVE-2026-9082, is under active mass exploitation. The flaw is an unauthenticated SQL injection that affects Drupal sites configured to use a PostgreSQL database. With a CVSS v3.1 score of 9.8 (Critical), the vulnerability can be exploited by a remote, unauthenticated attacker to execute arbitrary SQL commands. This can lead to a complete compromise of the site, including data theft, unauthorized privilege escalation, and potentially remote code execution (RCE). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-9082 to its Known Exploited Vulnerabilities (KEV) catalog, confirming widespread attacks and requiring federal agencies to patch immediately.
CVE ID: CVE-2026-9082
Severity: Critical (CVSS 9.8)
Vulnerability Type: SQL Injection
Authentication: Not required
Attack Vector: Network
The vulnerability exists in a component of Drupal's database abstraction layer when processing certain SQL queries for PostgreSQL databases. An attacker can craft a malicious request to a vulnerable Drupal site and inject arbitrary SQL commands. Because no authentication is needed, this flaw is particularly dangerous and easily weaponized for automated, large-scale attacks. Successful exploitation grants the attacker the same level of database access as the Drupal application itself, which often means full read/write access to all site data.
The vulnerability affects Drupal core sites that meet the following criteria:
Sites using other databases like MySQL or MariaDB are not affected by this specific flaw.
As predicted by the Drupal security team, exploitation began almost immediately after the patch was released. Security firms are tracking thousands of automated attack attempts from a wide range of IP addresses. The addition of CVE-2026-9082 to the CISA KEV catalog serves as definitive proof of active, in-the-wild exploitation. Attackers are scanning the internet for vulnerable Drupal sites to compromise them at scale.
The impact of a successful exploit is severe. An attacker can:
The following patterns may help identify vulnerable or compromised systems:
url_patternSELECT, UNION, CAST.log_sourcefile_nameprocess_namehttpd, nginx, php-fpm spawning shell processes like sh, bash, or whoami.The Cyber Security Agency of Singapore (CSA) has confirmed active exploitation of CVE-2026-9082, urging immediate patching for all Drupal sites.
Applying the security patch provided by Drupal is the most critical and effective mitigation.
Using a Web Application Firewall (WAF) can provide a layer of defense by blocking malicious requests before they reach the application.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.