High-risk vulnerabilities found in Drupal extensions, patch required
CERT-BUND released a high-risk advisory (WID-SEC-2026-3554) on September 23, 2026, concerning multiple vulnerabilities in Drupal extensions. The advisory aggregates 36 CVE identifiers, including CVE-2026-96355, which could allow attackers to execute arbitrary code, escalate privileges, bypass security, or manipulate data. These vulnerabilities exist in the contributed modules layer of the open-source CMS, not in Drupal's core installation. Site administrators must manually inventory and update all affected extensions, as patches are not delivered through the core update channel. Compensating controls like restricting administrative access are recommended where immediate patching is not possible.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in