Vulnerabilità · 130 giorni fa
Il rischio reale qui non è l'advisory. È la finestra di upgrade stessa, perché Drupal afferma che gli exploit potrebbero seguire entro ore o giorni e che i dettagli della fix arriveranno nello stesso momento delle patch. I team che non possono testare e applicare rapidamente le modifiche potrebbero perdere l'unica finestra pratica di remediation.
4 fonti che coprono questa storia
Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
Drupal admins rushing to patch maximum severity SQL injection vulnerability
IT environments using Symfony and Twig also need to update.
Drupal critical update to fix bug with high exploitation risk
Drupal has announced a "core security release" scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure.
Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation
Drupal says attackers may develop an exploit for the vulnerability within hours or days.
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
Drupal plans May 20 core security patches as exploits may follow within hours or days, requiring urgent site updates.
Part of the PlainSec briefing for 2026-05-21