Attackers have started exploiting a critical Drupal vulnerability shortly after developers disclosed the issue publicly. The flaw, tracked as CVE-2026-9082, affects Drupal websites that use PostgreSQL databases and allows SQL injection through crafted requests. Security researchers warned that threat actors would likely move quickly after the advisory appeared. Active exploitation attempts now confirm those concerns.…
A new Drupal critical update fixes a severe vulnerability that security researchers believe could face rapid exploitation shortly after disclosure. The Drupal Security Team warned administrators to prepare immediate maintenance windows and patch exposed systems as quickly as possible. The advisory affects multiple supported Drupal core branches and even several unsupported versions that received emergency…