Vendor

Drupal

As of , 5 Drupal vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2019-6340.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2019-6340Remote Code ExecutionDrupal CorePatch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry0.92
2CVE-2018-7600Remote Code ExecutionDrupal Drupal CorePatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2026-9082SQL InjectionDrupal CorePatch this weekMetasploit module0.16
4CVE-2018-7602Remote Code ExecutionDrupal CorePatch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry0.99
5CVE-2020-13671Un-restricted Upload of FileDrupal Drupal corePatch soon0.35

Products

  • Core3 entries
  • Drupal core2 entries

Added each year

1232021: 1120212022: 3320222023: nonenone20232024: nonenone20242025: nonenone20252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20223
2023none
2024none
2025none
20261

Used in ransomware