Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning Vulnerability overview CERT-BUND advisory WID-SEC-2026-3554 covers a batch of vulnerabilities in contributed Drupal projects, published 23 September 2026 and rated high risk. The batch spans CVE-2026-96355 to CVE-2026-96398 and contains 36 identifiers, with CVE-2026-96362 among them. The subject is contributed code. Externally visible…

The CERT-BUND advisory WID-SEC-2026-3554 details a set of vulnerabilities (CVE-2026-96355 to CVE-2026-96398) impacting 36 contributed Drupal projects. CVE-2026-96362 is among these identifiers. The advisory, published on 23 September 2026, assigns a high risk rating to the batch of issues. The vulnerabilities stem from contributed code within Drupal installations and can lead to arbitrary code execution, extended privileges, security control bypass, data manipulation, and cross-site scripting.

External scanning tools, such as ZoomEye, may not accurately identify affected sites due to the nature of the vulnerabilities. The impact of these vulnerabilities can be severe, potentially exposing sensitive data, compromising hosting accounts, and affecting compliance. To remediate, operators should compare their internal Drupal inventory against the list of affected projects and versions, updating to the fixed releases for the specific branch they are using.

For modules that cannot be updated promptly, disabling them may serve as a mitigation strategy. Drupal core is not included in the affected list, and any vulnerable instances below the fixed version remain at risk.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

How to Automate Job Outreach Without Landing in Spam

You wrote a script that finds hiring managers and emails them about your candidacy. It worked for a week. Then the replies stopped, and you assumed nobody was interested. Nobody was reading.

  • Implement SPF, DKIM, and DMARC for email authentication
  • Gradually warm-up email sending volume and monitor engagement
  • Randomize sending behavior, personalize emails, and verify addresses

Making seamless video loops with ffmpeg: repeat, ping-pong, crossfade and a generated bridge

Disclosure: I build LoopVideo , a browser-based tool for making video loops. The ffmpeg techniques below work on their own, with or without it. This post was written with the help of AI tools.

  • Normalize video clips for consistent frame rates, sizes, and pixel formats
  • Repeat clip with -streamloop flag for simplest seamless loop
  • Use ping-pong technique to play clip forward and backward for boomerang effect

More from Thursday 1 October →