CISA orders feds to patch actively exploited Drupal vulnerability
…and media organizations. Google/Mandiant researcher Michael Maturi discovered this vulnerability (now tracked as CVE-2026-9082 ) in Drupal's database abstraction API. The security flaw can be exploited without authentication, allowing…
