惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
IT之家
IT之家
博客园_首页
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
GbyAI
GbyAI
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Help Net Security
T
Tailwind CSS Blog
B
Blog RSS Feed
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 叶小钗
雷峰网
雷峰网
量子位

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
CVE-2026-9082: Drupal’s Highly Critical SQL Injection Fla...
Pierluigi Paganini · 2026-05-24 · via Security Affairs

Attackers began exploiting Drupal SQL injection flaw CVE-2026-9082 within 48 hours of patch release.

Drupal issued a highly critical security patch on May 20 for CVE-2026-9082, a SQL injection vulnerability that allows unauthenticated attackers to compromise sites running PostgreSQL databases. The project maintainers warned ahead of the release that exploits could surface within hours or days. That prediction was accurate; exploitation attempts started almost immediately, and within 48 hours, security firms were tracking thousands of attacks in the wild.

The vulnerability sits in an API designed to sanitize database queries and prevent SQL injection. A flaw in that API means an attacker can send specially crafted requests and inject arbitrary SQL commands on sites using PostgreSQL. As Drupal put it in its advisory.

“A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks.” reads the advisory. “This vulnerability can be exploited by anonymous users.”

The result can range from information disclosure to privilege escalation and, in some configurations, remote code execution.

Not every Drupal site is affected, the flaw only impacts those running PostgreSQL as the database backend, which Drupal estimates at under 5 percent of all installations. That still translates to thousands of potentially vulnerable sites given that Drupal powers hundreds of thousands of websites globally, many of them in government, higher education, media, and enterprise environments.

The advisory for CVE-2026-9082 was updated on May 22, two days after the patch released, with a detail that confirmed what many had already suspected:

“The risk score has been updated to reflect that exploit attempts are now being detected in the wild.” reads the updated advisory.

Drupal uses the NIST CVSS scoring system where the maximum possible rating is 25, so a score of 23 puts this firmly in the “drop everything and patch” category.

Imperva researchers published data showing just how quickly attackers moved. The security firm reported observing over 15,000 exploitation attempts targeting nearly 6,000 sites across 65 countries in the first two days after disclosure. Almost half of those attacks were aimed at gaming and financial services websites, sectors where both credential theft and financial data access have immediate monetization paths.

“Since CVE-2026-9082 was released, Imperva has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries. Attacks are primarily targeting Gaming and Financial Services sites so far, at collectively almost 50% of all attacks.” states Imperva. “This pattern suggests attackers and scanners are primarily attempting to identify exposed Drupal sites running vulnerable PostgreSQL-backed configurations. While the activity is currently dominated by reconnaissance and validation, the nature of the vulnerability means successful exploitation could quickly move from probing to data extraction or privilege escalation.”

Top targeted countries are the U.S. (61.8%), Singapore (6.6%), and Australia (6.3).

That is the detail that matters most for defenders right now. What is being observed at scale is still largely reconnaissance, attackers mapping out which sites are vulnerable, testing exploits, and confirming they work. The fact that it has not yet escalated to widespread data theft or system compromise is not a reason to wait. It is a window that will close.

For administrators running Drupal sites on PostgreSQL, the action is straightforward: apply the patch immediately. For those running MySQL or MariaDB, the vulnerability does not apply, but verifying which database backend a site is using is worth doing rather than assuming. And for anyone managing Drupal infrastructure who has not patched yet and is seeing unusual database query patterns or failed authentication attempts in logs, it is worth treating those as potentially hostile and investigating promptly.

The pattern Imperva is observing, widespread reconnaissance followed by selective exploitation, is how these campaigns typically unfold. The current phase is mapping. The next phase is harvesting. The window to get ahead of that transition is narrow and shrinking.

The last time Drupal saw active exploitation of a highly critical flaw was back in 2019, when a remote code execution bug was hit within days of the patch going live. Before that, the flaws known as Drupalgeddon and Drupalgeddon2 made headlines for being weaponized at scale to compromise tens of thousands of sites. Since 2019, Drupal’s track record has been notably cleaner, highly critical vulnerabilities have been rare, and when they do appear, widespread exploitation has not followed.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Drupal)