CVE-2026-96357 in Drupal: 16 modules, 19 affected version ranges
CERT-BUND advisory WID-SEC-2026-3554 covers CVE-2026-96357 in 16 contributed Drupal modules across 19 affected version ranges. The flaw is rated high risk with a CVSS 3.1 base score of 9.8 and temporal score of 8.5, is remotely exploitable, and fixes are available.
- CERT-BUND: 16 Drupal projects, 19 affected version ranges
- CVSS 3.1 base score 9.8, temporal score 8.5, high risk
- Modules include Webform, Project Browser and Editoria11y
- ZoomEye: 436,263 Drupal instances visible on 25 September
Read next
Security