CERT-BUND Flags High-Risk Drupal Vulnerabilities Across 16 Modules, Patches Available
Germany's CERT-BUND published advisory WID-SEC-2026-3554 on 23 September 2026, flagging a cluster of 36 vulnerabilities spanning CVE-2026-96355 to CVE-2026-96398 across 16 contributed Drupal modules. The flaws are remotely exploitable over HTTP and can lead to arbitrary code execution, privilege escalation, security bypass, data manipulation, and cross-site scripting. The advisory assigned maximum damage and probability scores of 4 out of 4, with a CVSS v3.1 base score of 9.8 and a temporal score of 8.5, placing the overall risk rating at high. Fixed releases have been identified for all 16 affected modules, including Webform, Project Browser, and Editoria11y, while Drupal core is not affected. A ZoomEye scan conducted on 26 September 2026 indexed over 436,000 Drupal assets globally, though the advisory does not directly link those installations to the vulnerable modules.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in