{"id":"CVE-2018-7602","title":"A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x","summary":"A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"drupal","product":"drupal","affected":["drupal >= 7.0, < 7.59","drupal >= 8.4.0, < 8.4.8","drupal >= 8.5.0, < 8.5.3","debian_linux = 7.0","debian_linux = 8.0","debian_linux = 9.0"],"patched":["drupal 8.5.3"],"published":"2018-07-19","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-7602","references":[{"url":"http://www.securityfocus.com/bid/103985","label":"mlhess@drupal.org"},{"url":"http://www.securitytracker.com/id/1040754","label":"mlhess@drupal.org"},{"url":"https://lists.debian.org/debian-lts-announce/2018/04/msg00030.html","label":"mlhess@drupal.org"},{"url":"https://www.debian.org/security/2018/dsa-4180","label":"mlhess@drupal.org"},{"url":"https://www.drupal.org/sa-core-2018-004","label":"mlhess@drupal.org"},{"url":"https://www.exploit-db.com/exploits/44542/","label":"mlhess@drupal.org"},{"url":"https://www.exploit-db.com/exploits/44557/","label":"mlhess@drupal.org"},{"url":"http://www.securityfocus.com/bid/103985","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1040754","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2018/04/msg00030.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2018/dsa-4180","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.drupal.org/sa-core-2018-004","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/44542/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/44557/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7602","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99236,"epssPercentile":0.99936,"kev":true,"kevDateAdded":"2022-04-13","kevDueDate":"2022-05-04","kevRansomware":true,"exploited":true,"exploitAvailable":true,"ingestedAt":"2026-08-13T06:00:54.362Z","exploits":{"exploitdb":true,"github":5,"githubRepos":["https://github.com/1337g/Drupalgedon3","https://github.com/happynote3966/CVE-2018-7602","https://github.com/kastellanos/CVE-2018-7602"],"nuclei":["CVE-2018-7602"],"checkedAt":"2026-09-19T16:22:50.594Z"},"slug":"CVE-2018-7602","body":"## Overview\n\nA remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.\n\n## Affected\n\n- `drupal >= 7.0, < 7.59`\n- `drupal >= 8.4.0, < 8.4.8`\n- `drupal >= 8.5.0, < 8.5.3`\n- `debian_linux = 7.0`\n- `debian_linux = 8.0`\n- `debian_linux = 9.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `drupal 8.5.3`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":19.8,"exploitation":25,"ransomware":5},"changes":[]}