Drupal team announced a security advisory for a vulnerability
(CVE-2018-7600) reported by Jasper Mattsson and rated as Highly Critical
with a score of 21/25 based on the NIST Common Misuse Scoring System. A
remote code execution vulnerability exists within multiple subsystems
of Drupal 7.x and 8.x. This potentially allows attackers to exploit
multiple attack vectors on a Drupal site. Successful exploitation could
lead to a potential compromise of the web application and possibly the
underlying operating system as well.
Recomendations :
Update your drupal instance !!!
PoC Exploits :
https://github.com/a2u/CVE-2018-7600/blob/master/exploit.py
https://github.com/dreadlocked/Drupalgeddon2
Reasearch:
https://research.checkpoint.com/uncovering-drupalgeddon-2/