· via dev.to (home feed)
CERT-BUND advisory covers 36 CVEs across 16 contributed Drupal projects
A high-risk CERT-BUND advisory lists 36 CVEs affecting 16 contributed Drupal projects, with the batch scored up to CVSS 9.8. Nineteen fixed releases cover the group; Drupal core is not affected.

What the advisory covers
A high-risk advisory from CERT-BUND, WID-SEC-2026-3554, published on 23 September 2026, bundles 36 vulnerability identifiers running from CVE-2026-96355 to CVE-2026-96398. According to a dev.to analysis of the record, those identifiers map to 16 contributed Drupal projects — add-on modules maintained independently of the Drupal core codebase, which is not covered by the advisory.
The record confirms that exploitation is possible remotely and that fixes have shipped, but it stops short of describing how each individual CVE works. The outcome classes it flags include arbitrary code execution, extended privileges, bypass of security measures, data manipulation or disclosure, and cross-site scripting.
The 16 affected projects
The advisory names Webform, Webform REST, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST & JSON API Authentication, Stop administrator login, Tawk.to Live chat application, Editoria11y Accessibility Checker, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content, and Diba carousel slider.
Patched versions stretch from Webform 6.2.12 and 6.3.1 up to Diba carousel slider 3.0.2. As the dev.to write-up points out, 19 fixed releases were needed to cover 16 projects, which means some projects shipped more than one patch — and teams need to match the fix to the branch they actually run.
Severity and real-world exposure
The batch is recorded with damage and probability ratings of 4 out of 4, a CVSS v3.1 base score of 9.8 and a temporal score of 8.5, according to the dev.to report. Those numbers describe how badly the affected code paths can fail, not evidence of ongoing attacks: the record reports no confirmed exploitation campaign.
For scale, a ZoomEye search for Drupal deployments on 26 September 2026 returned 436,344 assets. That figure counts any Drupal installation, not sites running one of the 16 listed modules, so it is an upper bound on exposure rather than a measurement of it. A ZoomEye query keyed to CVE-2026-96361 returned zero results, meaning the identifier is not indexed as an exposed service.
Fixes and operator guidance
The dev.to analysis draws a structural distinction worth internalizing: Drupal core security releases arrive on a published cadence with a defined support window behind them, while contributed projects patch on their maintainers' own schedules. This batch — one advisory, 16 projects, 19 releases — is what that fragmentation looks like in practice.
The practical guidance from the write-up:
- Run contributed modules as a maintenance track separate from core, with their own update review.
- Keep an inventory of which modules in your estate still receive security releases.
- Apply the fixed release for each affected project, matching the release to the branch in use.
- Drop modules whose maintainers have stopped issuing fixes.
- Where a project shipped two fixed releases, record which branch you run so the next advisory resolves faster.
Why it matters
Most Drupal teams have their core update process down cold, because core publishes on a schedule. Contributed modules are where that discipline tends to break: 16 projects can carry remotely exploitable flaws scored this high, and nothing forces maintainers and site owners to move in sync. Advisories like WID-SEC-2026-3554 are a reminder that a Drupal site's security posture is the union of core plus every enabled module — and that a module inventory needs to be as current as the code itself.
- #drupal
- #security
- #cve
- #cms
- #open-source