Drupal: Critical SQL injection flaw now targeted in attacks
2026-05-22T13:23:29Z•d653543fa6c44584b45b433269c8fe7d1bad54b82bf75624d8586ea29f41ea84
active-exploitationbotnetchromiumciscocrypto-drainerdrupalfirst-vpngithubinfostealerjfmbackdoorkimwolfmalwaremfa-bypassmicrosoft-defenderremote-code-executionsecure-workloadshowboatsonicwallsql-injectionsupply-chaintanstackubiquitiunifi-osvpn-seizurezero-day
What happened
Multiple high-impact security stories from BleepingComputer: Drupal disclosed a "highly critical" SQL injection vulnerability that is being actively exploited; Ubiquiti and Cisco released patches for maximum-severity flaws (UniFi OS and Secure Workload respectively); Microsoft rolled fixes for exploited Defender zero-days; and Google accidentally leaked details of an unfixed Chromium issue that could allow remote code execution. Other notable items include SonicWall VPN MFA bypasses tied to incomplete patching, a law-enforcement takedown of a VPN service used in ransomware/data-theft, arrest(s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d653543fa6c44584b45b433269c8fe7d1bad54b82bf75624d8586ea29f41ea84
- Enrichment time
- 2026-05-22T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.