U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog
2026-05-24T08:51:48Z•4618a5a73da9b1545ba6b29185327a1adbeda1e703e68547e2b91df982577aac
active-exploitationapp-store-fraudbotnetc2-infrastructurecisacobalt-strikecve-2025-34291cve-2026-9082drupalextortion-ransomwarefirst-vpnghostwriterhunt.iokimwolfknown-exploited-vulnerabilitieslaw-enforcementpatchingphishingpostgresqlsql-injectiontrend-micro
What happened
Multiple Security Affairs reports highlight a high-impact Drupal Core SQL injection (CVE-2026-9082) that affects sites using PostgreSQL: Drupal released a critical patch on May 20 and exploit activity was observed within 48 hours; CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The feed also notes other KEV additions (e.g., Trend Micro Apex One CVE-2025-34291 and additional Microsoft/Adobe/ConnectWise entries), a resurgence of the Ghostwriter APT using a Ukrainian learning platform for Cobalt Strike/phishing, the arrest of a suspected Kimwolf botnet operator, a global
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 4618a5a73da9b1545ba6b29185327a1adbeda1e703e68547e2b91df982577aac
- Enrichment time
- 2026-05-24T08:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.