Skip to content
COOEY

EXPOSURES › CVE-2018-7600

CVE-2018-7600

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-7600 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

A critical Drupal Core vulnerability allowed attackers to execute arbitrary code on compromised sites, actively exploited and linked to ransomware activity.

CVE-2018-7600 represents a remote code execution flaw in Drupal Core, enabling complete site compromise. DIB organizations using Drupal must immediately patch to prevent ransomware and data breaches, impacting CMMC compliance. Failure to remediate promptly exposes systems to significant risk.

Shame score — The vulnerability's active exploitation and ransomware linkage demonstrate a serious and preventable security failure in a widely-used platform.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -1.00
cooey ↗ severe-fallout -1.00
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.