Skip to main content

CVE detail

CVE-2026-9082

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

CVSS 9.8 · CriticalBuzz score 73.9KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 73.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 5.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
5.0
1 repos · best confidence 0.99
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • 25th May – Threat Intelligence ReportCheck Point Research

    eys, cracked WordPress accounts, and drained a crypto wallet. VULNERABILITIES AND PATCHES Microsoft published fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited Windows Defender flaws affecting the Malware Protection Engine and Defender Antimalware Platform. The first allows local privilege escalation, while the second can cause denial

    vendorresearch.checkpoint.comMay 25, 2026, 3:08 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack Why pure extortion is […]

    newssecurityaffairs.comMay 24, 2026, 11:51 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Microsoft Exchange Server, tracked as CVE-2026-9082 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. Drupal issued a highly critical security patch on May […]

    newssecurityaffairs.comMay 24, 2026, 7:54 AM
  • Attackers began exploiting Drupal SQL injection flaw CVE-2026-9082 within 48 hours of patch release. Drupal issued a highly critical security patch on May 20 for CVE-2026-9082, a SQL injection vulnerability that allows unauthenticated attackers to compromise sites running PostgreSQL databases. The project maintainers warned ahead of the release that exploits could surface within hours or […]

    newssecurityaffairs.comMay 23, 2026, 4:17 PM
  • Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.

    newswww.securityweek.comMay 22, 2026, 5:15 PM
  • CVE-2026-9082Horizon3.ai

    CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core affecting PostgreSQL-backed deployments. The flaw allows unauthenticated attackers to execute arbitrary SQL queries and potentially compromise affected environments.

    exploithorizon3.aiMay 21, 2026, 8:53 PM
  • CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.

    newswww.securityweek.comMay 21, 2026, 10:58 AM
  • Administrators of the Drupal open source content management platform are rushing to install an emergency patch issued today to fix a “highly critical” SQL injection vulnerability in the application’s core. While the vulnerability only affects websites that use the PostgreSQL database, there may be upstream issues with Symfony, a set of PHP packages and web […]

    newswww.csoonline.comMay 20, 2026, 11:58 PM
  • No excerpt available.

    Mitigationwww.cisa.govMay 20, 2026, 8:16 PM
  • https://www.drupal.org/sa-core-2026-004www.drupal.org

    No excerpt available.

    Vendor Advisorywww.drupal.orgMay 20, 2026, 8:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 0 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence