ClosedMedium impactAI Generated

CISA Adds Drupal Core SQL Injection Vulnerability (CVE-2026-9082) to Known Exploited Vulnerabilities Catalog

Occurred 22 May 2026·Detected 23 May 2026·
🇺🇸 CISA Headquarters, Washington D.C., USA; advisory applies broadly to U.S. federal networks and all Drupal-using organizations globally.1 reportEnded 29 May 2026
Cyber

CISA has added CVE-2026-9082, a Drupal Core SQL Injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies are required to remediate the vulnerability by a specified due date under BOD 22-01, while all organizations are strongly urged to prioritize remediation as part of their vulnerability management practices.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: Second-pass historical recalibration. This cyber advisory or vulnerability item is relevant to Cyber and technology-dependent Property/Casualty books, but it does not evidence confirmed insured loss, claims activity, ransomware/business interruption, critical infrastructure outage, or quantified market impact sufficient for HIGH.

View assessment methodology

How we grade what we know -- Known · Reported · Uncertain. Methodology →

Geographic Zone Matches

1 active match

  • TRIA Certified Areas
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇺🇸 United States

Timeline

Status Change2 Jun 2026, 13:05

Lifecycle changed

monitoring → closed

Closure2 Jun 2026, 13:05

Event Closed

auto_closed_monitoring_timeout

Status Change29 May 2026, 05:30

Status changed to monitoring

Auto-transitioned: no updates for 6 hours

active → monitoring

Status Change28 May 2026, 22:34

Status changed to active

evidence_trigger: authoritative_fast_track

signal → active

De-escalation25 May 2026, 17:12

Impact changed

high → medium

Initial Detection23 May 2026, 21:10

Initial Detection

CISA has added CVE-2026-9082, a Drupal Core SQL Injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies are required to remediate the vulnerability by a specified due date under BOD 22-01, while all organizations are strongly urged to prioritize remediation as part of their vulnerability management practices.

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9082 Drupal Core SQL Injection Vulnerability. This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

Source: CISA Advisories (Official Advisory) · View source

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts