Drupal Product Security Update Advisory (CVE-2026-9082)
Overview A security update has been released to address a vulnerability in the Drupal product. the vulnerability is CVE-2026-9082, a SQL injection (SQL injection, an attack that maliciously manipulates database queries) vulnerability in Drupal core. Affected the following Drupal core versions are affected 8.9.0 and above but below 10.4.10. 10.5.0

