Drupal known exploited vulnerabilities
CISA lists 5 Drupal CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-05-22), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2018-7600 (Drupal Core): EPSS 100.0%, added 2021-11-03
- CVE-2018-7602 (Core): EPSS 99.2%, added 2022-04-13
- CVE-2019-6340 (Core): EPSS 92.0%, added 2022-03-25
- CVE-2020-13671 (Drupal core): EPSS 35.4%, added 2022-01-18
- CVE-2026-9082 (Core): EPSS 15.7%, added 2026-05-22
Most affected Drupal products
Core (3), Drupal core (1), Drupal Core (1).
All Drupal CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-9082 | Core | Core SQL Injection | 2026-05-22 | 2026-05-27 | 15.7% | – |
| CVE-2018-7602 | Core | Core Remote Code Execution | 2022-04-13 | 2022-05-04 | 99.2% | Yes |
| CVE-2019-6340 | Core | Core Remote Code Execution | 2022-03-25 | 2022-04-15 | 92.0% | – |
| CVE-2020-13671 | Drupal core | core Un-restricted Upload of File | 2022-01-18 | 2022-07-18 | 35.4% | – |
| CVE-2018-7600 | Drupal Core | Core Remote Code Execution | 2021-11-03 | 2022-05-03 | 100.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors