CISA Flags Exploited Drupal SQL Injection Flaw. Drupal Won't Say Who Got Hit.
CVE-2026-9082 is in the Known Exploited Vulnerabilities catalog. The advisory mentions active exploitation. It does not mention victims, telemetry, or how anyone found out.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-9082, an SQL injection bug in Drupal Core, to its Known Exploited Vulnerabilities catalog this week, citing evidence of active exploitation. The flaw carries a CVSS score of 6.5 and affects all supported versions of the open-source CMS. Federal civilian agencies have three weeks to patch under Binding Operational Directive 22-01.
That is the official record. Here is what is missing from it.
The KEV entry does not name a threat actor. It does not describe the exploitation activity, the victim sector, or the source of the telemetry. I asked CISA's press office on Tuesday whether the agency was relying on its own incident response data or a partner submission. The reply, from a spokesperson who declined to be named, was that CISA "does not comment on specific sources of exploitation evidence." The agency has a standing public process for KEV nominations. It rarely shows its working.
Drupal's own security advisory describes the bug as exploitable by an attacker with the ability to influence query parameters, and credits the fix to the Drupal security team. The advisory does not mention in-the-wild exploitation at all. I emailed the Drupal Association on Monday asking whether the project was aware of attacks before CISA's listing, and whether any maintainers had been contacted by victims or incident responders. (The Drupal Association has not responded. A second email sent Wednesday morning also went unanswered.)
A CVSS of 6.5 is not catastrophic on paper. SQL injection in a CMS that powers federal agency sites, university portals, and a long tail of municipal government pages is another matter. Drupal still runs a meaningful slice of .gov properties. The KEV listing implies someone, somewhere, is using this against real targets right now.
So who?
The pattern matters because Drupalgeddon (CVE-2014-3704) and Drupalgeddon2 (CVE-2018-7600) both went from patch to mass exploitation within days, and both ended up powering cryptomining botnets and webshell campaigns for years afterwards. Nobody I spoke to this week wanted to predict the same arc for 9082 on the record. Off the record, two incident responders at separate North American firms told me they had not yet seen the exploit in their own data, but were actively hunting for it.
The CISA deadline for federal patching is firm. The vendor advisory is published. The exploit details are not, which is normal, and the victim details are not, which is also normal, and that is exactly the problem with reading KEV entries as a complete picture of what is happening.
Who is being hit, and since when?



