Executive Summary A highly critical vulnerability (CVE-2026-9082, Drupal risk score 20/25) was disclosed affecting Drupal core versions 8.9.0 through 11.3.9, allowing attackers to execute arbitrary SQL commands via the database abstraction API on PostgreSQL-backed sites. Due to the potential for full data exposure, privilege escalation, and remote code execution, immediate patching is required. About the […] The post Critical Drupal SQL Injection Exposes PostgreSQL-Backed Sites to Remote Code Execution appeared first on Orca Security .