CERT-BUND Flags 16 Drupal Modules at Critical Risk Under CVE-2026-96357
CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026, identifies 16 contributed Drupal modules across 19 affected version ranges under CVE-2026-96357, carrying a critical CVSS v3.1 base score of 9.8. The vulnerability is rated high risk, remotely exploitable, and impacts modules including Webform, Project Browser, REST & JSON API Authentication, and Smart Content, among others. All 36 identifiers share a common impact profile covering arbitrary code execution, privilege escalation, security bypass, data tampering, and cross-site scripting. A ZoomEye scan conducted on 25 September 2026 found over 436,000 publicly visible Drupal instances, though not all necessarily run the affected modules. Site administrators are advised to audit installed modules against the affected ranges and apply fixes detailed in Drupal security advisories sa-contrib-2026-154 through sa-contrib-2026-191, verifying the installed version after updating.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in