EXPOSURES › CVE-2018-7600
CVE-2018-7600
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA critical Drupal Core vulnerability allowed attackers to execute arbitrary code on compromised sites, actively exploited and linked to ransomware activity.
CVE-2018-7600 represents a remote code execution flaw in Drupal Core, enabling complete site compromise. DIB organizations using Drupal must immediately patch to prevent ransomware and data breaches, impacting CMMC compliance. Failure to remediate promptly exposes systems to significant risk.
Shame score — The vulnerability's active exploitation and ransomware linkage demonstrate a serious and preventable security failure in a widely-used platform.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.