Skip to main content

Drupal security briefs

2 published alerts for Drupal products and services.

Actively exploited (KEV)Ransomware

CVE-2018-7602

Drupal Core Remote Code Execution Vulnerability

Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7602). A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CISA remediation due date: 2022-05-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-7600

Drupal Core Remote Code Execution Vulnerability

Drupal Drupal Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-7600). Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.