Build1 publisher2 min readPublished Updated
CERT-BUND's high-risk Drupal advisory puts 36 CVEs in 16 contributed modules
CERT-BUND has rated 36 CVEs in 16 contributed Drupal projects high risk, and Drupal core is not listed as affected. Each site team has to check the modules it has installed against 19 fixed releases and confirm that the code serving requests actually changed.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CERT-BUND published the advisory as WID-SEC-2026-3554 on 23 September 2026.
- One shared sentence covers the impact of the whole batch: code execution, privilege gain, bypassed security controls, data manipulation and disclosure, and cross-site scripting.
- Webform (6.2.12, 6.3.1), Project Browser (2.0.3, 2.1.5) and Editoria11y Accessibility Checker (2.2.23, 3.0.9) each shipped fixes on two supported branches.
- A ZoomEye query on 26 September found 436,349 Drupal assets, and a query for the batch's CVE-2026-96362 returned zero.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision A core update leaves every version on this list where it was, so the work happens per site: list the contributed modules and branches actually installed, then move each one to its branch's fixed release.
- constraint The CERT-BUND record alone cannot rank the 36 identifiers by exploitability. Until each project advisory is read, any listed module a site runs has to be handled as a possible code-execution path.
- exposure Cross-site scripting in a minor add-on runs in every authenticated session that loads the page, so administrators who open those pages are exposed through code they may not remember installing.
The identifiers run from CVE-2026-96355 to CVE-2026-96398 [2]. That span covers 44 numbers and the batch holds 36 of them. A scanner rule that matches the whole range will therefore flag eight identifiers that are not in this batch [1].
A write-up of the advisory on dev.to explains how a bug in a contributed module gets reached. A contributed module is PHP code that runs inside Drupal's request cycle, usually with the privileges of the web server user [7]. A flaw becomes reachable when an anonymous or low-privilege visitor can get to the vulnerable controller, form or AJAX callback, and the attacker's input lands in a sink the module failed to protect [7].
The web user's privileges decide how far a compromise goes. Drupal keeps its database credentials in settings.php [8]. Code running as the web user frequently reaches that configuration, along with stored data well beyond the affected module [8].
The per-project detail is in the structured record's version list [10]. Thirteen of the projects have one fixed release each: Webform REST 4.2.1, Cloud 7.0.1, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST & JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to Live chat application 3.0.4, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1 and Diba carousel slider 3.0.2 [12]. Add two each for the three two-branch projects and you get all 19 fixes [2]. Where a project has two fixed releases, the write-up advises reading that project's advisory before choosing a target version [18].
ZoomEye's large count is the number of Drupal deployments visible in its index [15]. According to the write-up, sizing exposure from it would take knowing which contributed modules each site runs, and at what version [15]. Its author treats the zero as a result about the index and not as evidence that no deployment is affected [15]. A zero for an identifier three days after the advisory came out mostly describes how far the index has caught up [3].
For a module that cannot be updated right away, the write-up says to disable or remove it [16]. Disabling takes the module's routes out of the request cycle, and the author rates that above blocking paths at a proxy [16]. I agree, and the reason is in the advisory itself. It publishes no per-CVE root cause, no proof of concept and no list of affected routes, so a proxy rule would be written against paths nobody has listed [5].
Drupal caches aggressively [17]. A container image or an unapplied database update can leave a correct-looking version string in front of vulnerable code [17].
What to watch
- Per-project advisories that map each of the 36 identifiers to an impact class and the affected routes, which would let teams rank the patches.
- Public proof-of-concept code or exploitation reports for any of the 16 listed projects.
- ZoomEye or another index starting to return nonzero results for CVE-2026-96362 or other identifiers in the batch.