20/05/2026
Drupal has released SA-CORE-2026-004 fixing a highly critical SQL injection vulnerability affecting PostgreSQL-backed Drupal installations.
Tracked as CVE-2026-9082, the issue impacts Drupal core’s database abstraction layer and may allow anonymous exploitation leading to information disclosure, privilege escalation, or further attacks.
The Drupal Security Team issued emergency releases for supported branches alongside mitigation updates for several unsupported versions because of the severity of the vulnerability.
Read more:
https://bit.ly/4eTtA7w