CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8
CERT-BUND published advisory WID-SEC-2026-3554 on 23 September 2026 covering 36 CVEs (CVE-2026-96355 to 96398) in 16 contributed Drupal projects. The risk is rated high with CVSS v3.1 base 9.8 and temporal 8.5, allowing remote code execution, privilege escalation and data disclosure. Drupal core is excluded and each module has a fixed release.
- 36 CVEs across 16 Drupal projects, core excluded
- CVSS v3.1 base 9.8, temporal 8.5, high risk
- Fixes include Webform 6.3.1, Cloud 7.0.1, AI CKEditor 1.4.3
- ZoomEye counts 436,344 Drupal assets, no module mapping
Read next
Security