Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms

May 29, 2026

Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

May 29, 2026

Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems

May 29, 2026
Facebook X (Twitter) Instagram
Friday, May 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
News

Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

Team-CWDBy Team-CWDMay 29, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure.

The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org. Drupal said the vulnerability resides in a database abstraction API that is used in Drupal Core to validate queries and ensure they are sanitized against SQL injection attacks.

“A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases,” it said. “This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks.”

Drupal noted the security flaw can be exploited by anonymous users, and impacts only sites that use PostgreSQL. The following versions address the issue –

  • Drupal 11.3.10
  • Drupal 11.2.12
  • Drupal 11.1.10
  • Drupal 10.6.9
  • Drupal 10.5.10
  • Drupal 10.4.10

Drupal 7 isn’t affected. The releases for supported branches (versions 11.3, 11.2, 10.6, and 10.5) include upstream security updates for Symfony and Twig, making it essential that the latest versions are installed.

As previously disclosed by Drupal, manual patches have also been released for Drupal versions 9 and 8, which have reached end-of-life –

“Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage,” Drupal said. “Drupal 8 and Drupal 9 have both reached end-of-life. 

“Due to this issue’s severity, the unsupported releases and patches for unsupported versions are provided as a best effort. Those unsupported versions will still have other, previously disclosed security vulnerabilities.”

Update

Searchlight Cyber has released two working proof-of-concept (PoC) code for CVE-2026-9082, stating the vulnerability can be exploited by anonymous users on any deployment that backs Drupal with PostgreSQL.

“Both are gated on PostgreSQL being the database backend, so MySQL and SQLite installs are not exploitable through these paths,” researchers Patrik Grobshäuser, Kevin Gervot, and Tomais Williamson said. “The upgrade is still worth picking up on those installs for the bundled Symfony and Twig advisories that the same Drupal release carries.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSilent Ransom Group Uses In-Person IT Impersonation to Breach Systems
Next Article Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms
Team-CWD
  • Website

Related Posts

News

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms

May 29, 2026
News

Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems

May 29, 2026
News

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

2025’s most common passwords were as predictable as ever

January 21, 2026

What to consider before asking an AI chatbot for health advice

May 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.