chiprook
← Security
SecurityOctober 4, 2026, 09:00

CVE-2026-96364 in Drupal: 16 modules affected, detection only by version

CERT-BUND issued advisory WID-SEC-2026-3554 for CVE-2026-96364, affecting 16 contributed Drupal modules including Webform, Cloud and Project Browser. The remotely exploitable flaw carries a CVSS 3.1 base score of 9.8, and patches are available, but no detection trigger is published, so verification must rely on installed module versions.

CVE-2026-96364 in Drupal: 16 modules affected, detection only by version
#Drupal#Webform#CERT-BUND
Read next
Security

CERT-BUND flags 36 Drupal module flaws, including Webform and REST API

Security

CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8

Security

CVE-2026-96366 in Drupal Webform: managed file access bypass

Security

CVE-2026-96363 Is a Webform Entity Print Submodule Issue, Not Drupal Core