CVE-2026-96364 in Drupal: 16 modules affected, detection only by version
CERT-BUND issued advisory WID-SEC-2026-3554 for CVE-2026-96364, affecting 16 contributed Drupal modules including Webform, Cloud and Project Browser. The remotely exploitable flaw carries a CVSS 3.1 base score of 9.8, and patches are available, but no detection trigger is published, so verification must rely on installed module versions.
- CVE-2026-96364 affects 16 Drupal modules, including Webform, Cloud and Project Browser
- CVSS 3.1 base score 9.8, temporal 8.5, remotely exploitable
- Fixes released: Webform 6.2.12/6.3.1, Cloud 7.0.1, Project Browser 2.0.3/2.1.5
- ZoomEye returned 436,388 Drupal assets but zero matches for the CVE
Read next
Security