High-risk Drupal vulnerabilities batch includes 36 CVEs, urges immediate updates
CERT-BUND published a high-risk advisory (WID-SEC-2026-3554) on September 23, 2026, covering 36 vulnerabilities affecting contributed Drupal projects. The batch, which includes CVE-2026-96369, received a CVSS v3.1 base score of 98 and a temporal score of 85, indicating severe risk. Potential outcomes include arbitrary code execution, privilege escalation, security bypass, data manipulation, and cross-site scripting. The advisory lists sixteen specific Drupal projects that require immediate updating to their fixed versions to mitigate the threats. A scan on September 28, 2026, identified over 436,000 Drupal assets potentially exposed to these vulnerabilities.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in