CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack

2026-05-24T02:51:44Z3a2b7e9d69abd3b20c12529b62ce48d6cd4247ebaffe3567dca2263be78b281a
active-exploitationapp-fraudappleaptbotnetc2-infrastructurecisacobalt-strikedrupalextortionfirst-vpnghostwriterhostingkimwolfknown-exploited-vulnerabilitieslaw-enforcementmfa-bypassphishingpostgreSQLransomwaresonicwallsql-injectiontrend-micro

What happened

Multiple high-impact incidents reported: Drupal released a highly critical patch for CVE-2026-9082 — a SQL injection affecting sites using PostgreSQL — with active exploitation observed within 48 hours of the May 20 fix. U.S. CISA added several flaws (including Trend Micro Apex One CVE-2025-34291) to its Known Exploited Vulnerabilities catalog. Other notable items: Ghostwriter (UAC-0057/UNC1151) resumed phishing against Ukrainian government targets using a legitimate learning platform to deliver Cobalt Strike; SonicWall Gen6 VPN MFA bypasses persisted due to missed remediation steps; law-enfor

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3a2b7e9d69abd3b20c12529b62ce48d6cd4247ebaffe3567dca2263be78b281a
Enrichment time
2026-05-24T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.