DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-9082PUBLISHED: 2026-05-20
CRITICALCVE-2026-9082★ CISA KEV LISTED

Drupal Core PostgreSQL Unauthenticated SQL Injection

VENDOR: Drupal//PRODUCT: Drupal Core
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A highly critical SQL injection vulnerability in Drupal Core's PostgreSQL EntityQuery condition handler (SA-CORE-2026-004) allows fully unauthenticated attackers to inject arbitrary SQL via the JSON login endpoint or JSON:API filter parameters. Successful exploitation can lead to information disclosure, privilege escalation, and in some configurations remote code execution via pg_exec(). CISA added CVE-2026-9082 to KEV on May 22, 2026 after Imperva observed over 15,000 attack attempts targeting nearly 6,000 sites across 65 countries within 48 hours of disclosure.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSDrupal 8.0.0 through 11.3.9 (PostgreSQL backends only); fixed in 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10
  • https://www.drupal.org/sa-core-2026-004
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html
  • https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/
  • https://nvd.nist.gov/vuln/detail/CVE-2026-9082
SHARE BRIEF:✕ Post on Xin Share on LinkedIn