CVE-2026-96355: 36 Drupal extension flaws across six impact classes
CERT-BUND advisory WID-SEC-2026-3554, released 2026-09-23, aggregates 36 CVEs in Drupal contributed modules with a high risk rating, spanning XSS, data disclosure, security bypass, privilege escalation and arbitrary code execution. ZoomEye found 436,318 internet-facing Drupal assets but zero matches for the specific CVE. Fixes must be applied per module, since core updates do not cover contributed code.
- 36 CVEs in Drupal extensions bundled into one high-risk advisory
- ZoomEye: 436,318 Drupal hosts online, 0 matches for CVE-2026-96355
- Contributed module fixes are not delivered via the core update channel
- Arbitrary PHP code execution is the most severe impact class
Read next
Security