Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
5.9
CVE-2026-55803EXPLOITEDPATCHED
drupal · drupal

Drupal core - Critical - PHP object injection - SA-CORE-2026-005

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Affected Products

VendorProductVersions
drupaldrupal0.0.0, 10.6.0, 11.2.0, 11.3.0, 0.0.0, 0.0.0

References

  • https://www.drupal.org/sa-core-2026-005

Related News (3 articles)

Tier D
Help Net Security4d ago
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
→ No new info (linked only)
Tier C
VulDB44d ago
CVE-2026-55803 | Drupal up to 11.3.11 Core injection
→ No new info (linked only)
Tier B
CERT-FR67d ago
Multiples vulnérabilités dans Drupal (18 juin 2026)
→ No new info (linked only)
CVSS 3.15.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.5.1210.6.1111.2.1411.3.1211.0.*11.1.*
CWECWE-915
PublishedJul 10, 2026
Last enriched44d agov2
Trending Score30
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Drupal Internationalization Single Sign-On Access Bypass
Trending: 1
CRITICALCVE-2026-11913
Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
Trending: 1
MEDIUMCVE-2026-15083EXP
ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
LOWCVE-2026-11909EXP
Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
LOWCVE-2026-55807EXP
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: affectedVersions, severity, activelyExploited
Jul 11, 2026
Actively Exploited
Jul 13, 2026
Patch Available
Jul 13, 2026

Version History

v2
Last enriched 44d ago
v2Tier C44d ago

Updated affected versions to include 11.3.11, changed severity to CRITICAL, and noted that no exploit exists.

affectedVersionsseverityactivelyExploited
via VulDB
v144d ago

Initial creation