# Drupal patches RCE, SQLi, SSRF flaws

Published: 2026-06-18 · Severity: high
Canonical: https://vorant.io/reports/66ead571-154e-5a7c-a1e5-e8461e5b9b10/drupal-patches-rce-sqli-ssrf-flaws

> Multiple vulnerabilities in Drupal versions 10.5–11.3 enable remote code execution, SQL injection, and server-side request forgery; patches available.

France's CERT-FR has issued an advisory covering multiple critical vulnerabilities affecting Drupal core versions 10.5.x through 11.3.x. The flaws include remote code execution, SQL injection (SQLi), server-side request forgery (SSRF), cross-site scripting (XSS), and security policy bypass. Affected versions span Drupal 10.6.x prior to 10.6.11, 11.2.x prior to 11.2.14, 11.3.x prior to 11.3.12, and all versions prior to 10.5.12.

Drupal has released five security advisories (SA-CORE-2026-005 through SA-CORE-2026-009) dated June 17, 2026, addressing five distinct CVEs: CVE-2026-55803, CVE-2026-55804, CVE-2026-55806, CVE-2026-55807, and CVE-2026-55808. The combination of RCE and SQLi capabilities presents a significant attack surface for threat actors targeting content management systems.

Organizations running affected Drupal versions should prioritize patching to the latest releases. The advisory references vendor security bulletins for detailed remediation guidance. Given Drupal's widespread use in government, education, and media sectors, exploitation attempts may follow once technical details become publicly available.

## Mentioned in this report

- Vulnerabilities: CVE-2026-55803, CVE-2026-55804, CVE-2026-55806, CVE-2026-55807, CVE-2026-55808

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0771/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/66ead571-154e-5a7c-a1e5-e8461e5b9b10/drupal-patches-rce-sqli-ssrf-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
