Post
CRITICAL

Drupal Patches Unauthenticated RCE Flaw CVE-2026-9082

· vulnerability · cve · rce · privilege-escalation

The Drupal security team patched CVE-2026-9082, classified “highly critical,” which allows unauthenticated attackers to exploit public-facing Drupal installations for information disclosure, privilege escalation, and remote code execution. No account or prior access is required.

Drupal sites that have not yet applied the patch should be treated as potentially at risk; apply the latest Drupal core update immediately. If patching cannot occur within hours, consider temporarily restricting public access to the affected installation until the fix is applied.