Drupal is rolling out an emergency security update on May 20. You cannot miss it

2026-05-19T20:51:43Z6041e5084bb2535be00fce3ff0994a8e015726f949b02c34730734fc745b223e
CVE-2020-17103CVE-2026-42945Drupal emergency updateGrafana GitHub tokenINTERPOLMicrosoft Fox TempestMiniPlasmaNGINXOperation RamzS3 misconfigurationShai-HuludShinyHuntersTabiqWindows privilege escalationcldflt.sysdata breachmalware-signing-as-a-servicesupply-chain

What happened

A batch of high-impact security stories: Drupal will push an emergency update on May 20 (admins should apply immediately); a critical NGINX vulnerability (CVE-2026-42945, CVSS 9.2) is being actively exploited; Chaotic Eclipse released a MiniPlasma Windows SYSTEM privilege-escalation exploit tied to cldflt.sys (related to CVE-2020-17103); Microsoft disrupted a malware-signing-as-a-service operation dubbed Fox Tempest; Shai-Hulud worm source leakage spawned immediate copycat attacks against NPM developers; Grafana confirmed a GitHub token compromise (source code exposure, no customer systems); 7

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6041e5084bb2535be00fce3ff0994a8e015726f949b02c34730734fc745b223e
Enrichment time
2026-05-19T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.