ArticleMay 20, 20261 min read

Drupal Security Update SA-CORE-2026-004: NodeHive SaaS Already Patched

abstract background
Tags
DrupalSecurityNodeHive SaaS

NodeHive SaaS The Drupal Security Team has published a highly critical security advisory today: SA-CORE-2026-004 (CVE-2026-9082). The vulnerability allows SQL injection attacks on Drupal sites using PostgreSQL and can be exploited without authentication.

NodeHive SaaS: Already patched

All NodeHive SaaS instances have been updated. No action is required from our SaaS customers.

If you run a self-hosted NodeHive setup, update your Drupal core to the latest patched version immediately.

Our recommendation

Anyone running a standalone Drupal installation should apply the update now. The full list of patched versions is available in the official advisory (https://www.drupal.org/sa-core-2026-004).

Last updated: May 20, 2026
Newsletter
More Articles

Continue Reading