Core vulnerabilities
1 published alerts for Drupal Core.
Actively exploited (KEV)Ransomware
Drupal Core Remote Code Execution Vulnerability
Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7602). A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.