What happened
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
Affected versions
Core: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 44557Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)SixP4ck3r2018-04-30VerifiedExploit-DB 44542Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)Blaklis2018-04-25VerifiedSploitusExploit for CVE-2018-7602. CVSS 9.8.Sploitus index2026-09-15T10:56:42+00:00CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.