CISA has issued an urgent warning to U.S. federal agencies over a newly exploited Drupal vulnerability, giving them until Wednesday evening to patch affected systems. The issue is not just another routine CMS bug. It is an SQL injection flaw that has already been seen in real-world attacks, which makes the response window much shorter and far more serious.

