INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Drupal's Highly Critical SQL Injection Flaw Under Active Attack
| 2026-05-23 16:17 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Attackers began exploiting a highly critical SQL injection flaw in Drupal, CVE-2026-9082, within 48 hours of its patch release on May 20. The vulnerability allows unauthenticated attackers to compromise sites running PostgreSQL databases, and it has already been detected in the wild by security firms tracking thousands of attacks. Thousands of potentially vulnerable sites are affected globally, with an estimated under 5% using PostgreSQL as their database backend, which translates to hundreds of thousands of websites across various sectors including government, higher education, media, and enterprise environments. Attackers can exploit this vulnerability through reconnaissance and validation, leading to information disclosure, privilege escalation, remote code execution, or other attacks, with Imperva researchers observing over 15,000 exploitation attempts targeting nearly 6,000 sites in the first two days after disclosure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-9082 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-9082CVE-2026-9082
Target & Sectors
FIVE_EYES
FIVE_EYES
financefinance
mediamedia
Incident Timeline
2026/05/23
Attackers began exploiting Drupal SQL injection flaw CVE-2026-9082 within 48 hours of patch release.
Click on any entity below to view its context and source!
infrastructure
6.5
The vulnerability in question is
CVE-2026-9082
(CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core.
infrastructure
8.9
Impact and recommendations
CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Dru…
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
infrastructure
10.4
Impact and recommendations
CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Dru…
infrastructure
11.3.10
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediately to the latest version available for their…
infrastructure
11.2.12
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediately to the lat…
infrastructure
11.1.10
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to…
infrastructure
10.6.9
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…al versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owner…
infrastructure
10.5.10
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…2 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x…
infrastructure
10.4.10
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…recommendations
CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x…
infrastructure
9.5
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
infrastructure
10.5
…CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12…
infrastructure
10.6
…range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10…
infrastructure
11.0
…luding:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administra…
infrastructure
11.1
…Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are…
infrastructure
11.2
…efore 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediat…
infrastructure
11.3
…efore 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediately to the latest version avail…
Tactical Metrics
Metrics
infrastructure
6.5
Software Version
Click for context!
The vulnerability in question is
CVE-2026-9082
(CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core.
Metrics
infrastructure
11.3.10
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediately to the latest version available for their…
Metrics
infrastructure
11.2.12
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediately to the lat…
Metrics
infrastructure
11.1.10
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to…
Metrics
infrastructure
10.6.9
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…al versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owner…
Metrics
infrastructure
10.5.10
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…2 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x…
Metrics
infrastructure
10.4.10
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
…recommendations
CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x…
Metrics
infrastructure
9.5
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
Metrics
infrastructure
8.9
Software Version
Patches are available for the following versions -
Drupal 11.3.10
Drupal 11.2.12
Drupal 11.1.10
Drupal 10.6.9
Drupal 10.5.10
Drupal 10.4.10
Drupal 9.5 (Manual patching required)
Drupal 8.9 (Manual patching required)
Impact and recommendations
CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Dru…
Metrics
infrastructure
10.4
Software Version
Impact and recommendations
CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Dru…
Metrics
infrastructure
10.5
Software Version
…CVE-2026-9082 impacts a broad range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12…
Metrics
infrastructure
10.6
Software Version
…range of Drupal versions, including:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10…
Metrics
infrastructure
11.0
Software Version
…luding:
Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administra…
Metrics
infrastructure
11.1
Software Version
…Drupal 8.9.x
Drupal 10.4.x before 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are…
Metrics
infrastructure
11.2
Software Version
…efore 10.4.10
Drupal 10.5.x before 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediat…
Metrics
infrastructure
11.3
Software Version
…efore 10.5.10
Drupal 10.6.x before 10.6.9
Drupal 11.0.x / 11.1.x before 11.1.10
Drupal 11.2.x before 11.2.12
Drupal 11.3.x before 11.3.10
Website owners and administrators are recommended to upgrade immediately to the latest version avail…
Intelligence Sources
The Hacker News
2026-05-23
Security Affairs
2026-05-23
BleepingComputer
2026-05-22
Drupal: Critical SQL injection flaw now targeted in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
Drupal’s Highly Critical
entity
16x
infrastructure
Software Version
6.5
version
8x
timeline
Temporal Reference
May 20
date
8x
attribution
Attributing Entity
API
authority
3x
general metric
%
62
%
3x
industry
Targeted Sector
Government
sector
3x
tactic
Cyber Operation Type
Privilege Escalation
tactic
3x
general metric
Drupal
9
drupal
2x
target region
Target Country
Singapore
country
Contextual Telemetry
Context Block
11 METRICS
general metric
Australia
6
australia
vulnerability
Exploited CVE
CVE-2026-9082
cve
general metric
Hours
48
hours
general metric
Attack Attempts
15,000
attack attempts
general metric
Individual Sites
6,000
individual sites
general metric
Countries
65
countries
general metric
Percent
5
percent
general metric
Score
6
score
general metric
10.4.10 Drupal
10
10.4.10 drupal
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.