chiprook
← Security
SecuritySeptember 27, 2026, 10:00

CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8

CERT-BUND published advisory WID-SEC-2026-3554 on 23 September 2026 covering 36 CVEs (CVE-2026-96355 to 96398) in 16 contributed Drupal projects. The risk is rated high with CVSS v3.1 base 9.8 and temporal 8.5, allowing remote code execution, privilege escalation and data disclosure. Drupal core is excluded and each module has a fixed release.

CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8
#Drupal#CERT-BUND
Read next
Security

F5 patches exploited CVSS 9.8 flaw in BIG-IP APM

Policy

Philippines Ombudsman flags 'Ghost Internet' projects

Security

Microsoft fixes 974 CVEs in September 2026 Patch Tuesday

Security

CVSS 10.0 VeloCloud Orchestrator flaw actively exploited