Security News CISA orders feds to patch actively exploited Drupal vulnerability BleepingComputer Daniel Bender 26 May 2026 Share CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited.