CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.

Drupal plans May 20 core security patches as exploits may follow within hours or days, requiring urgent site updates.

The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches