CERT-Bund Flags High-Risk Drupal Vulnerability Affecting 16 Contributed Modules
CERT-Bund published advisory WID-SEC-2026-3554 on 23 September 2026, identifying a high-risk vulnerability cluster that includes CVE-2026-96365 and spans 36 CVE identifiers across 16 contributed Drupal modules. The advisory carries a CVSS v3.1 base score of 9.8 and warns of potential remote exploitation leading to arbitrary code execution, privilege escalation, data disclosure, and cross-site scripting. Affected modules include Webform, Project Browser, Commerce Decoupled Checkout, REST & JSON API Authentication, and others, each with specific fixed releases already available. Agencies managing multiple Drupal client sites face a compounded patching challenge, as updates must be scheduled per site rather than per module. Experts recommend grouping sites by shared modules to streamline testing, removing unused modules, and maintaining per-site version records to speed response to future advisories.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in