CVE-2026-96358: 436,276 Drupal Fingerprints Don't Mean Vulnerable Sites
CERT-BUND issued advisory WID-SEC-2026-3554 on 23 September 2026 covering multiple flaws in 16 contributed Drupal modules, including Webform and AI CKEditor. ZoomEye counted 436,276 hosts running Drupal, but that figure does not represent vulnerable sites because it ignores installed modules and their versions.
- Advisory WID-SEC-2026-3554 covers 19 version ranges across 16 Drupal modules
- ZoomEye: 436,276 Drupal hosts and zero matches for CVE-2026-96358
- The flaws allow code execution, privilege escalation and XSS attacks
- Vendor fixes exist; in-range modules must be updated and rechecked
Read next
Security