U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog

2026-05-24T08:51:48Z4618a5a73da9b1545ba6b29185327a1adbeda1e703e68547e2b91df982577aac
active-exploitationapp-store-fraudbotnetc2-infrastructurecisacobalt-strikecve-2025-34291cve-2026-9082drupalextortion-ransomwarefirst-vpnghostwriterhunt.iokimwolfknown-exploited-vulnerabilitieslaw-enforcementpatchingphishingpostgresqlsql-injectiontrend-micro

What happened

Multiple Security Affairs reports highlight a high-impact Drupal Core SQL injection (CVE-2026-9082) that affects sites using PostgreSQL: Drupal released a critical patch on May 20 and exploit activity was observed within 48 hours; CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The feed also notes other KEV additions (e.g., Trend Micro Apex One CVE-2025-34291 and additional Microsoft/Adobe/ConnectWise entries), a resurgence of the Ghostwriter APT using a Ukrainian learning platform for Cobalt Strike/phishing, the arrest of a suspected Kimwolf botnet operator, a global

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
4618a5a73da9b1545ba6b29185327a1adbeda1e703e68547e2b91df982577aac
Enrichment time
2026-05-24T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.