<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/drupal.xml</id>
  <title>Exploit Radar: exploited Drupal vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for Drupal products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/drupal.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/drupal/"/>
  <updated>2026-05-22T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-9082/</id>
    <title>CVE-2026-9082 — Drupal Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-9082/"/>
    <updated>2026-05-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Drupal; if none are available, stop using the product. For cloud services, follow the guidance from Drupal. CISA deadline: 5 days. Added to CISA’s catalog of exploited vulnerabilities on May 22, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-7602/</id>
    <title>CVE-2018-7602 — Drupal Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-7602/"/>
    <updated>2022-04-13T00:00:00Z</updated>
    <summary type="text">Apply the security update from Drupal. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 13, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-6340/</id>
    <title>CVE-2019-6340 — Drupal Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-6340/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Drupal. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-13671/</id>
    <title>CVE-2020-13671 — Drupal Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-13671/"/>
    <updated>2022-01-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from Drupal. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on January 18, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-7600/</id>
    <title>CVE-2018-7600 — Drupal Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-7600/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Drupal. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
