<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Drupal</title><description>Actively exploited vulnerabilities affecting Drupal products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/drupal.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-9082 — Drupal Core SQL Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-9082</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-9082</guid><description>Drupal&apos;s database abstraction API contains a SQL injection flaw that attackers can exploit by sending specially crafted requests. Successful exploitation can lead to privilege escalation — allowing an attacker to gain higher-level access than intended — and potentially remote code execution, meaning an attacker could run arbitrary code on the server. Any organization running Drupal Core is at risk, and compromise of the web server or underlying data could follow.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>Drupal</category><category>Core</category></item></channel></rss>