Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1932 articles · 155881 vulns · 36/41 feeds (7d)
← Back to list
6.6
CVE-2026-6366EXPLOITEDPATCHED
drupal · drupal

Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Affected Products

VendorProductVersions
drupaldrupal8.0.0, 10.6.0, 11.0.0, 11.3.0

References

  • https://www.drupal.org/sa-core-2026-002

Related News (1 articles)

Tier C
VulDB6d ago
CVE-2026-6366 | Drupal up to 10.5.8/10.6.6/11.2.10/11.3.6 dynamically-determined object attributes (sa-core-2026-002)
→ No new info (linked only)
CVSS 3.16.6 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.5.910.6.711.2.1111.3.7
CWECWE-915
PublishedMay 19, 2026
Last enriched6d agov2
Trending Score18
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-9082EXPKEV
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
Trending: 157
CRITICALCVE-2026-8495
Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037
Trending: 27
MEDIUMCVE-2026-6367EXP
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
Trending: 24
NONECVE-2026-4929EXP
Simple Hierarchical Select (Drupal 7) XSS in term-derived output
Trending: 23
NONECVE-2026-4093EXP
Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)
Trending: 19

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 19, 2026
Discovered by ZDM
May 19, 2026
Updated: severity, affectedVersions, activelyExploited
May 20, 2026
Actively Exploited
May 21, 2026
Patch Available
May 21, 2026

Version History

v2
Last enriched 6d ago
v2Tier C6d ago

Updated severity to MEDIUM, added new affected versions, and noted that no exploit is available.

severityaffectedVersionsactivelyExploited
via VulDB
v16d ago

Initial creation