Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch
Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch Overview CVE-2026-96364 is one of 36 CVE identifiers carried by CERT-BUND advisory WID-SEC-2026-3554, titled Drupal Erweiterungen: Mehrere Schwachstellen, first published on 23 September 2026. That advisory is rated high in the German risk scheme. Its machine-readable record sets a remotely exploitable flag to true and…
The September 2026 Drupal contributed-module batch includes 36 CVE identifiers, as outlined in the CERT-BUND advisory WID-SEC-2026-3554. This batch affects 16 contributed Drupal projects, such as Webform, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST and JSON API Authentication, Stop administrator login, Tawk.to live chat application, Editoria11y Accessibility Checker, Webform REST, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content, and Diba carousel slider.
The advisory rates the vulnerability as high in the German risk scheme, with a CVSS version 3.1 base score of 98 and a temporal score of 85. It is important to note that the advisory does not provide a one-to-one mapping from each CVE identifier to each product reference, and it does not include proof of concept, payload, or reproduction sequence.
Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.