CyberMax
Home › Exploited CVEs

Drupal known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 Drupal CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-05-22), and 2 are known to be used in ransomware campaigns.

Drupal CVEs added to CISA KEV per year
2021: 1202112022: 3202232026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Drupal products

Core (3), Drupal core (1), Drupal Core (1).

All Drupal CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-9082CoreCore SQL Injection2026-05-222026-05-2715.7%–
CVE-2018-7602CoreCore Remote Code Execution2022-04-132022-05-0499.2%Yes
CVE-2019-6340CoreCore Remote Code Execution2022-03-252022-04-1592.0%–
CVE-2020-13671Drupal corecore Un-restricted Upload of File2022-01-182022-07-1835.4%–
CVE-2018-7600Drupal CoreCore Remote Code Execution2021-11-032022-05-03100.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors