Drupal: Critical SQL injection flaw now targeted in attacks

2026-05-22T13:23:29Zd653543fa6c44584b45b433269c8fe7d1bad54b82bf75624d8586ea29f41ea84
active-exploitationbotnetchromiumciscocrypto-drainerdrupalfirst-vpngithubinfostealerjfmbackdoorkimwolfmalwaremfa-bypassmicrosoft-defenderremote-code-executionsecure-workloadshowboatsonicwallsql-injectionsupply-chaintanstackubiquitiunifi-osvpn-seizurezero-day

What happened

Multiple high-impact security stories from BleepingComputer: Drupal disclosed a "highly critical" SQL injection vulnerability that is being actively exploited; Ubiquiti and Cisco released patches for maximum-severity flaws (UniFi OS and Secure Workload respectively); Microsoft rolled fixes for exploited Defender zero-days; and Google accidentally leaked details of an unfixed Chromium issue that could allow remote code execution. Other notable items include SonicWall VPN MFA bypasses tied to incomplete patching, a law-enforcement takedown of a VPN service used in ransomware/data-theft, arrest(s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d653543fa6c44584b45b433269c8fe7d1bad54b82bf75624d8586ea29f41ea84
Enrichment time
2026-05-22T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.