CVE-2018-7602
Executive Summary
CVE‑2018‑7602 is a remote code execution flaw in Drupal 7.x and 8.x core, allowing attackers to execute arbitrary code via multiple vectors. The vulnerability, classified as highly critical (SA‑CORE‑2018‑002), is actively exploited in the wild and listed on the CISA KEV. Immediate patching of Drupal installations is essential to prevent compromise.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2018-07-19T17:29:00.373 - Last Modified: 2026-10-02T14:54:58.763
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-04-13)
Original Description: A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
"Better than a thousand hollow words, is one word that brings peace."
— Buddha