High-Risk Vulnerabilities Found in 16 Popular Drupal Add-Ons
German cybersecurity agency CERT-BUND issued a high-risk advisory on September 23, 2026, covering 36 vulnerabilities in contributed Drupal projects. The batch of flaws, spanning identifiers from CVE-2026-96355 to CVE-2026-96398, includes risks like arbitrary code execution, privilege escalation, and data manipulation. Sixteen specific third-party Drupal modules, including Webform, Project Browser, and Commerce Decoupled Checkout, are named as affected. Drupal core itself is not impacted, but any installed version of the listed modules below the specified fixed version remains vulnerable. System administrators are advised to update the modules to their patched releases based on an internal inventory.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in