Drupal Critical SQL Injection Flaw CVE-2026-9082 Now Under Active Attack
May 23, 2026 Drupal has confirmed that a highly critical SQL injection vulnerability (CVE-2026-9082) in its core database abstraction API is now under active attack. Disclosed on May 18, 2026, the flaw allows unauthenticated remote attackers to execute…
Trend Micro Apex One Zero-Day Under Active Exploit
May 22, 2026 On May 22, 2026, Trend Micro disclosed a zero-day vulnerability in its enterprise endpoint protection platform, Apex One. The flaw is actively being exploited in the wild. Tracked as CVE-2026-34926, it is a directory traversal vulnerability…