CERT-BUND flags 36 Drupal module flaws, including Webform and REST API
CERT-BUND published advisory WID-SEC-2026-3554 on 23 September 2026 covering 36 vulnerabilities (CVE-2026-96355 to CVE-2026-96398) in contributed Drupal modules such as Webform, Webform REST and REST & JSON API Authentication. Fixed releases are available and Drupal core is not affected.
- Advisory WID-SEC-2026-3554 covers 36 CVEs in contributed Drupal modules
- Fixes include Webform 6.3.1, Webform REST 4.2.1 and REST & JSON API Authentication 3.2.0
- Scanners hit anonymously reachable Webform and REST API routes first
- Drupal core is outside the advisory; unpatched modules should be disabled
Read next
Security