Drupal has warned administrators to prepare for an emergency core security release affecting all supported branches, saying the undisclosed flaw is highly critical, easy to exploit, and could be weaponized within hours or days of disclosure. According to Drupal and follow-on reporting, the vulnerability requires no privileges and may let attackers expose non-public data or modify or delete site content, although it appears limited to certain uncommon configurations rather than every deployment. A related advisory from dCERT also flagged a Drupal Core vulnerability enabling an unspecified attack.
Security updates are scheduled for supported branches 11.3.x, 11.2.x, 10.6.x, and 10.5.x, with best-effort fixes also planned for older 11.1.x and 10.4.x releases. Sites running 8.9 and 9.5 are expected to receive manual patch files only, with warnings about possible regressions and renewed pressure to upgrade to supported versions such as Drupal 10.6 or later; Drupal 7 is not affected. Drupal Steward customers were said to be protected against known attack vectors, but Drupal still urged all organizations to reserve maintenance time and apply the patch immediately once released.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA added the actively exploited Drupal Core SQL injection flaw CVE-2026-9082 to its Known Exploited Vulnerabilities catalog after evidence of in-the-wild abuse. The agency ordered Federal Civilian Executive Branch agencies to remediate by 2026-05-27.
Imperva said that within 48 hours of Drupal's patch release, it observed more than 15,000 attack attempts exploiting CVE-2026-9082 against nearly 6,000 sites in 65 countries. The activity was largely reconnaissance and validation, with gaming and financial services organizations accounting for almost half of observed attacks.
Finland's Traficom warned that the critical Drupal Core SQL injection vulnerability is being actively exploited in the wild, particularly when Drupal uses PostgreSQL as its database. The notice said exploitation can lead to information disclosure and in some cases privilege escalation, arbitrary code execution, and other attacks, while reiterating upgrade guidance for supported and some end-of-life branches.
Drupal published its May 20, 2026 security advisory SA-CORE-2026-004 addressing a highly critical SQL injection vulnerability in multiple Drupal Core versions. The Canadian Centre for Cyber Security amplified the notice and urged administrators to review the advisory and apply updates or mitigations.
Germany's dCERT published Advisory 2026-1550 covering a Drupal Core vulnerability described as allowing an unspecified attack. The advisory reflects external coordination and public notice of the issue ahead of patch release.
Alongside the announcement, Drupal said the flaw is highly critical, easy to exploit without privileges, and could expose non-public data or allow modification or deletion of content, though only certain uncommon configurations are affected. It said supported branches 11.3.x, 11.2.x, 10.6.x, and 10.5.x would receive releases, best-effort patches would be provided for 11.1.x, 10.4.x, 9.5, and 8.9, Drupal 7 is unaffected, and older versions should be upgraded.
Drupal warned administrators on May 19, 2026 that it would release an emergency core security update on May 20 between 17:00 and 21:00 UTC for supported branches. The project urged site owners to reserve time to apply the fix immediately because exploits could appear within hours or days of disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
25 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcereddit.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourcetheregister.com
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.