{
  "id": 11396953,
  "title": "Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch",
  "url": "https://urgent.news/2026/10/02/reading-cve-2026-96364-in-the-september-2026-drupal-contributed",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T08:40:22.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/stark_zhuang_df5076f35c68/reading-cve-2026-96364-in-the-september-2026-drupal-contributed-module-batch-5dlb"
  },
  "original_language": "en",
  "account": null,
  "summary": "The September 2026 Drupal contributed-module batch includes 36 CVE identifiers, as outlined in the CERT-BUND advisory WID-SEC-2026-3554. This batch affects 16 contributed Drupal projects, such as Webform, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST and JSON API Authentication, Stop administrator login, Tawk.to live chat application, Editoria11y Accessibility Checker, Webform REST, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content, and Diba carousel slider. The advisory rates the vulnerability as high in the German risk scheme, with a CVSS version 3.1 base score of 98 and a temporal score of 85. It is important to note that the advisory does not provide a one-to-one mapping from each CVE identifier to each product reference, and it does not include proof of concept, payload, or reproduction sequence.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}