Vulnerabilità ed exploit
Il rischio reale qui non è l'advisory. È la finestra di upgrade stessa, perché Drupal afferma che gli exploit potrebbero seguire entro ore o giorni e che i dettagli della fix arriveranno nello stesso momento delle patch. I team che non possono testare e applicare rapidamente le modifiche potrebbero perdere l'unica finestra pratica di remediation.
4 fonti · 22 mag
SecurityWeek
Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
originaleCSO Online
Drupal admins rushing to patch maximum severity SQL injection vulnerability
IT environments using Symfony and Twig also need to update.
originaleBleepingComputer
Drupal critical update to fix bug with high exploitation risk
Drupal has announced a "core security release" scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure.
originalePart of the PlainSec briefing for 2026-05-19
Every edition of this story: La finestra delle patch di Drupal potrebbe chiudersi prima che finisca il testing