VORANT. Threat Intelligence Sign in Get the full feed

Drupal patches RCE, SQLi, SSRF flaws

high vulnerability

Multiple vulnerabilities in Drupal versions 10.5–11.3 enable remote code execution, SQL injection, and server-side request forgery; patches available.

France's CERT-FR has issued an advisory covering multiple critical vulnerabilities affecting Drupal core versions 10.5.x through 11.3.x. The flaws include remote code execution, SQL injection (SQLi), server-side request forgery (SSRF), cross-site scripting (XSS), and security policy bypass. Affected versions span Drupal 10.6.x prior to 10.6.11, 11.2.x prior to 11.2.14, 11.3.x prior to 11.3.12, and all versions prior to 10.5.12.

Drupal has released five security advisories (SA-CORE-2026-005 through SA-CORE-2026-009) dated June 17, 2026, addressing five distinct CVEs: CVE-2026-55803, CVE-2026-55804, CVE-2026-55806, CVE-2026-55807, and CVE-2026-55808. The combination of RCE and SQLi capabilities presents a significant attack surface for threat actors targeting content management systems.

Organizations running affected Drupal versions should prioritize patching to the latest releases. The advisory references vendor security bulletins for detailed remediation guidance. Given Drupal's widespread use in government, education, and media sectors, exploitation attempts may follow once technical details become publicly available.

Mentioned in this report

Vulnerabilities CVE-2026-55803CVE-2026-55804CVE-2026-55806CVE-2026-55807CVE-2026-55808

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0771/

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free