The Drupal Security Team recently released a highly critical security advisory, SA-CORE-2026-004 (CVE-2026-9082). While the headline highlights a severe SQL injection vulnerability, many site administrators are left wondering if they need to take action if they aren't using the affected database system.
Here is a simple breakdown of who is directly impacted and why an immediate update is necessary for all Drupal 10 and 11 websites.