CVE-2026-9082Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 1…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 3.1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 4 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 27, 2026
Last analysed / modified upstream
16%
Exploit-DB · 12 GitHub repos · Metasploit ×1 · Nuclei ×1 (last check)
Added to the CISA catalog on May 22, 2026. Federal remediation due May 27, 2026. View catalog ↗
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
drupal >= 8.9.0, < 10.4.10drupal >= 10.5.0, < 10.5.10drupal >= 10.6.0, < 10.6.9drupal >= 11.0.0, < 11.1.10drupal >= 11.2.0, < 11.2.12drupal >= 11.3.0, < 11.3.10Upgrade past the affected range:
drupal 11.3.10Connected by shared product, vendor, weakness, or advisory.
CVE-2018-7602Critical· 9.8A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x
CVE-2017-18362Critical· 9.8ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database
CVE-2019-7481High· 7.5Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources
CVE-2024-9379Medium· 6.5SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVE-2020-29574Critical· 9.8An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
CVE-2021-20016Critical· 9.8A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information