Vulnerability record · CVE-2018-7602 · published 19 July 2018
CVE-2018-7602: Drupal Core Remote Code Execution via Multiple Subsystems
DDrupal · Drupal
CVE-2018-7602 is a remote code execution flaw in multiple subsystems of Drupal 7.x and 8.x, related to SA-CORE-2018-002. It allows an attacker to compromise a Drupal site through multiple attack vectors, and both this flaw and the related one are being exploited in the wild.
Description
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, near-maximum EPSS, and public exploit code make this an urgent patching priority.
What it is
CVE-2018-7602 is a remote code execution flaw in multiple subsystems of Drupal 7.x and 8.x, related to SA-CORE-2018-002. It allows an attacker to compromise a Drupal site through multiple attack vectors, and both this flaw and the related one are being exploited in the wild.
Impact
Successful exploitation lets an attacker execute arbitrary code on the Drupal server, leading to full site compromise. This can result in data theft, webshell deployment, or use of the host for further attacks.
Attack surface
The flaw is network-reachable with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). It is exploited through Drupal's web interface across multiple subsystems.
Exploitation
It is listed in CISA KEV with known ransomware campaign use, has an EPSS 30-day probability of 0.99236 (99.9th percentile), and public exploit code exists in Exploit-DB (44542, 44557).
What to do
- Apply the vendor patch per Drupal SA-CORE-2018-004 and Debian DSA-4180 immediately.
- Upgrade to a supported Drupal release; Drupal 7.x and 8.x versions affected by this flaw are end-of-life or unsupported.
- If patching is not immediately possible, restrict or block access to affected Drupal endpoints and administrative interfaces.
- Monitor for and remove any webshells or unauthorized administrative accounts created before patching.
- Follow CISA KEV required action: apply updates per vendor instructions by the due date.
Detection
- Hunt for POST requests to Drupal endpoints with unusual parameters or serialized data consistent with known exploit chains.
- Monitor web server logs for requests matching public Exploit-DB PoCs (44542, 44557) and related SA-CORE-2018-002 patterns.
- Alert on new PHP files or modified core files in Drupal directories, which may indicate webshell placement.
- Review Drupal watchdog and access logs for unexpected administrative actions or authentication anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-7602 to the Known Exploited Vulnerabilities catalog on 13 April 2022 as "Drupal Core Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 4 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-7602 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-7602), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.