chiprook
← Security
SecurityOctober 2, 2026, 11:00

CVE-2026-96355: 36 Drupal extension flaws across six impact classes

CERT-BUND advisory WID-SEC-2026-3554, released 2026-09-23, aggregates 36 CVEs in Drupal contributed modules with a high risk rating, spanning XSS, data disclosure, security bypass, privilege escalation and arbitrary code execution. ZoomEye found 436,318 internet-facing Drupal assets but zero matches for the specific CVE. Fixes must be applied per module, since core updates do not cover contributed code.

CVE-2026-96355: 36 Drupal extension flaws across six impact classes
#Drupal
Read next
Security

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Security

CVE-2026-96366 in Drupal Webform: managed file access bypass

Security

CVE-2026-96357 in Drupal: 16 modules, 19 affected version ranges

Security

CVE-2026-96363 Is a Webform Entity Print Submodule Issue, Not Drupal Core