F5 Labs Details Drupal CVE-2026-9082 Scanning Patterns

Six-month stacked graph of the top 5 CVEs
F5 Labs

Sensor data published by F5 Labs adds a traffic-level view of CVE-2026-9082 exploitation attempts by focusing on how scanners probed Drupal JSON:API endpoints after disclosure. The report by F5 threat researcher Adam Metcalfe-Pearce says the company’s sensors recorded 576 attempts from nine source IPs between 20 May and 31 May 2026, with the first matching activity appearing on 22 May 2026.

The report’s useful detail is the observed scanning workflow. F5 Labs says requests rotated through common node content endpoints, including /jsonapi/node/article, /jsonapi/node/page, and /jsonapi/node/basic_page. The activity used the correct Accept: application/vnd.api+json header and tested boolean and time-based blind SQL injection conditions rather than sending generic probes.

F5 Labs also describes web application firewall evasion signals such as comment-based spacing, nested parentheses, PostgreSQL-specific casting, and use of pg_sleep(). The report characterises the activity as early-stage but purpose-built Drupal scanning because the nine source IPs shared similar request patterns and did not target other application types in F5’s sensor view. Its defensive advice centres on checking JSON:API access logs, reviewing public access to JSON:API, and using behaviour-based detection rather than static blocking alone.

Disclosure: This content is produced with the assistance of AI.

Disclaimer: The opinions expressed in this story do not necessarily represent that of TheDropTimes. We regularly share third-party blog posts that feature Drupal in good faith. TDT recommends Reader's discretion while consuming such content, as the veracity/authenticity of the story depends on the blogger and their motives. 

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events