Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation

2026-05-19T19:24:06Z52cf363553e29efea49aae04a39b5db152d8e4f8325d88b4deab3f1072040ee1
b1ack-stashchromadbcredit-card-theftdata-leakdirtydecryptdrupalfox-tempestindustrial-robotslinux-kernellolbinmalware-signingmshtaoperation-ramzpolyscopeprivilege-escalationrceremote-code-executionsupply-chainuniversal-robotszero-day

What happened

SecurityWeek feed (19 May 2026) highlights multiple high-risk incidents: Drupal plans an urgent patch for a 'highly critical' vulnerability at risk of rapid exploitation; an unpatched ChromaDB remote, unauthenticated RCE can lead to server takeover; PoC published for the DirtyDecrypt Linux kernel privilege-escalation bug; and CVE-2026-8153 allows OS command injection in Universal Robots PolyScope 5 (exposing industrial robot fleets). Microsoft disrupted the 'Fox Tempest' malware-signing service used to distribute signed malware, while attackers increasingly abuse the legacy MSHTA utility for L

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
52cf363553e29efea49aae04a39b5db152d8e4f8325d88b4deab3f1072040ee1
Enrichment time
2026-05-19T19:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.