OpsBuzz

Alert

Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 25, 2026, 11:08 PMSecurityhigh

Full content

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Vendor: Drupal

Product: Core

Due date: 2026-05-27

Known ransomware use: Unknown

Why it matters

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Related alerts