CVE-2026-9082 — exposed on the internet
CVE-2026-9082: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Drupal Drupal core
Internet exposure observed by OffSeq scans · last 30 days
Found on 4 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.
About CVE-2026-9082
CVE-2026-9082 is a critical SQL Injection vulnerability in Drupal core. It affects multiple versions starting from 8.9.0 and includes certain versions up to but not including 10.4.10, 10.5.10, 10.6.9, and 11.1. The vulnerability allows an attacker to execute arbitrary SQL commands, potentially leading to full compromise of confidentiality, integrity, and availability of the affected system. The CVSS score is 9.8, indicating a high severity with network attack vector and no required privileges or user interaction.
Vendor: DrupalCWE-89
OffSeq internet scanning found CVE-2026-9082 on 4 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.
Exposed-host countries
Exposed via
drupal