CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack

2026-05-23T20:51:52Zcf2dd2b7f30a39a38fd1a4490a3e844bd712ec0f0f318987199112cca4f11d4c
active-exploitationbotnetcisa-kevcobalt-strikecve-2008-4250cve-2025-34291cve-2026-9082drupalfirst-vpnghostwriterkimwolfmfa-bypasspatchingphishingpostgresqlransomware-extortionsonicwallsql-injection

What happened

The feed highlights a high-risk vulnerability CVE-2026-9082 — a Drupal unauthenticated SQL injection affecting sites using PostgreSQL — which was patched on May 20 and observed in active exploitation within 48 hours, creating an urgent need for immediate patching and verification. Other notable items: CISA added multiple flaws to its Known Exploited Vulnerabilities catalog (including CVE-2025-34291 and CVE-2008-4250), the Ghostwriter APT resumed phishing campaigns (delivering Cobalt Strike via a Ukrainian learning platform), law enforcement disrupted First VPN and arrested an alleged Kimwolf D

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
cf2dd2b7f30a39a38fd1a4490a3e844bd712ec0f0f318987199112cca4f11d4c
Enrichment time
2026-05-23T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.