Drupal critical update to fix bug with high exploitation risk
… The Drupal content management system CMS is very popular among large organizations as well as in the government, education, and healthcare sectors. …
… The Drupal content management system CMS is very popular among large organizations as well as in the government, education, and healthcare sectors. …
… The company says that admins should review /var/log/auth.log for entries showing "Accepted publickey for vmanage-admin" from unknown IP addresses: 2026-02-10T22:51:36+00:00 vm sshd 804 : Accepted publickey for vmanage-admin from port REDACTED PORT ssh2: RSA SHA256: REDACTED KEY Administrators shoul… …
… "After installing this update, domain controller discovery might fail on Windows Server 2016 systems when the server hostname is 15 characters long," Microsoft said . …
… Affected systems also experienced unexpected behavior, including reboots and, in some cases, system failures, depending on the installed drivers. …
… At this point, the actor could browse the file system, check environment variables, and execute commands remotely within the app's context. …
… The exploit could be leveraged to bypass the two-factor authentication 2FA protection in a popular open-source, web-based system administration tool that remains unnamed. …
… The content management system CMS project published a PSA on May 18, urging administrators to reserve time for core updates that addressed an issue that threat actors might start exploiting "within hours or days." The flaw is now tracked as CVE-2026-9082 and was discovered by Google/Mandiant resear… …
… During the intrusions, the hacker took between 30 and 60 minutes to log in, do network reconnaissance, test credential reuse on internal systems, and log out. …
… Its settings are now under Settings System Multitasking previously Nearby sharing . …
… This known issue is caused by insufficient free space on the EFI System Partition ESP , which results in the update automatically rolling back on affected devices. …