INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Drupal's Highly Critical SQL Injection Flaw Under Active Attack

| 2026-05-23 16:17 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Attackers began exploiting a highly critical SQL injection flaw in Drupal, CVE-2026-9082, within 48 hours of its patch release on May 20. The vulnerability allows unauthenticated attackers to compromise sites running PostgreSQL databases, and it has already been detected in the wild by security firms tracking thousands of attacks. Thousands of potentially vulnerable sites are affected globally, with an estimated under 5% using PostgreSQL as their database backend, which translates to hundreds of thousands of websites across various sectors including government, higher education, media, and enterprise environments. Attackers can exploit this vulnerability through reconnaissance and validation, leading to information disclosure, privilege escalation, remote code execution, or other attacks, with Imperva researchers observing over 15,000 exploitation attempts targeting nearly 6,000 sites in the first two days after disclosure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-9082 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-9082CVE-2026-9082
Target & Sectors
FIVE_EYES FIVE_EYES financefinance mediamedia
Incident Timeline
‎2026/05/23
Attackers began exploiting Drupal SQL injection flaw CVE-2026-9082 within 48 hours of patch release.
infrastructure 6.5
infrastructure 8.9
infrastructure 10.4
infrastructure 11.3.10
infrastructure 11.2.12
infrastructure 11.1.10
infrastructure 10.6.9
infrastructure 10.5.10
infrastructure 10.4.10
infrastructure 9.5
infrastructure 10.5
infrastructure 10.6
infrastructure 11.0
infrastructure 11.1
infrastructure 11.2
infrastructure 11.3
Tactical Metrics
Metrics
infrastructure
‎6.5
Software Version
Metrics
infrastructure
‎11.3.10
Software Version
Metrics
infrastructure
‎11.2.12
Software Version
Metrics
infrastructure
‎11.1.10
Software Version
Metrics
infrastructure
‎10.6.9
Software Version
Metrics
infrastructure
‎10.5.10
Software Version
Metrics
infrastructure
‎10.4.10
Software Version
Metrics
infrastructure
‎9.5
Software Version
Metrics
infrastructure
‎8.9
Software Version
Metrics
infrastructure
‎10.4
Software Version
Metrics
infrastructure
‎10.5
Software Version
Metrics
infrastructure
‎10.6
Software Version
Metrics
infrastructure
‎11.0
Software Version
Metrics
infrastructure
‎11.1
Software Version
Metrics
infrastructure
‎11.2
Software Version
Metrics
infrastructure
‎11.3
Software Version
Intelligence Sources