Drupal core received the highly critical security patch SA-CORE-2026-004 : unauthenticated SQL injection through the database access layer on PostgreSQL installations, with the possibility of data leakage and, in a bad scenario, privilege escalation or executable code. Attempts at exploitation in the wild have been recorded since 5/22/2026. For critical Drupal vulnerabilities, the window to attack is less than 24 hours today — speed is of the essence.
Who is affected?
- Drupal sites based on PostgreSQL (MySQL/MariaDB installations are outside the scope of this vulnerability)
- Out-of-date cores; also check the related SA-CORE-2026-005 (PHP object injection through JSON:API)
What to do now
- Update Drupal core to the version from the security release — without delay.
- Review logs for suspicious queries and accesses; check data integrity.
- If the site has been vulnerable for a long time, assume a compromise and conduct a review.
Are you running Drupal and not sure if you're patched? Send us the link — the diagnosis is free, and we'll get back to you within 5 minutes. Emergency Repair →
WMD — Super fast support.