Drupal released security updates for a highly critical Drupal Core vulnerability affecting sites that use PostgreSQL.
On December 30, 2024, a 'Chinese government-sponsored advanced persistent threat actor' breached a system managing confidential data for the U.S. Treasury Department. It was discovered that the ...
In its warning, Drupal said a vulnerability in this API allows an attacker to send specially crafted requests resulting in ...
US cyber authorities have added a critical Drupal Core SQL injection flaw to their exploited-vulnerabilities list after attacks began targeting unpatched websites using PostgreSQL databases, ...
Drupal has patched CVE-2026-9082, a highly critical vulnerability that could allow threat actors to hack websites.