Drupal released security updates for CVE-2026-9082, a highly critical SQL injection flaw in Drupal core that affects websites using PostgreSQL databases. The vulnerability stems from improper neutralization of special characters in user input within Drupal's database API, allowing an unauthenticated remote attacker to send crafted requests that can trigger SQL injection.
Successful exploitation could lead to information disclosure, privilege escalation, and in some environments potentially remote code execution. Drupal and downstream defenders urged administrators to upgrade to fixed versions 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, or 11.3.10, while manual patches were also issued for unsupported 8.9 and 9.5 branches; the flaw's severity was raised to CVSS 9.8 after initial scoring understated the risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability CVE-2026-9082 was initially assigned a CVSS score of 6.5, which was later increased to 9.8. Drupal classified the issue as highly critical.
Drupal developers released security updates for CVE-2026-9082, a highly critical SQL injection vulnerability in Drupal core affecting sites that use PostgreSQL. Fixed versions listed include 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10, with manual patches also provided for unsupported 8.9 and 9.5 branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.