Digital shields protecting against Drupal, KnowledgeDeliver, and Trend Micro exploits.

Daily Cybersecurity News - May 26, 2026

CISA Orders Feds to Patch Drupal Flaw

CISA told federal agencies to patch a Drupal SQL injection flaw by Wednesday evening.

The vulnerability lets unauthenticated attackers trigger SQL injection on PostgreSQL-backed Drupal sites. It is actively exploited in the wild.

Affects multiple Drupal versions running on government and public web servers.

CISA added the flaw to its Known Exploited Vulnerabilities catalog last week.

Hackers Exploited KnowledgeDeliver Zero Day for Web Shell Deployment

Attackers hit KnowledgeDeliver with a zero-day that let them drop web shells on servers.

Hardcoded machineKey values in a config file enabled ViewState deserialization for remote code execution. The flaw was zero-day at the time of use.

KnowledgeDeliver deployments running the affected configuration are exposed. Any server with the static keys in place can be targeted.

The attack chain started with ViewState tampering that led straight to shell upload.

Source: SecurityWeek

Trend Micro Apex One Path Traversal Exploited

A path traversal bug in Trend Micro Apex One is seeing real-world attacks right now.

CVE-2026-34926 lets attackers with Apex One Server access modify a key table and push malicious code to agents. Trend Micro confirmed zero-day exploitation and TrendAI spotted at least one attempt in the wild.

On-prem Apex One Server deployments are the main exposure. The flaw sits in the platform used by many enterprises for endpoint protection.

CISA issued a warning on the active exploitation.