Drupal Contributed Modules: 36 CVEs in One September 2026 Advisory Batch
What the advisory says
CERT-BUND published advisory WID-SEC-2026-3554 on 23 September 2026 and rated it high risk. The record collects 36 CVE identifiers, from CVE-2026-96355 through CVE-2026-96398, against contributed Drupal projects rather than Drupal core.
The affected projects are Webform, Webform REST, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST & JSON API Authentication, Stop administrator login, Tawk.to Live chat application, Editoria11y Accessibility Checker, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider.
The advisory describes consequences that span remote code execution, privilege escalation, security control bypass, data manipulation and disclosure, and cross-site scripting. That breadth matters for triage: an operator cannot assume a single exploit class and a single detection rule will cover the batch.
Why contributed modules drive the risk
Drupal core receives focused security attention and a predictable release rhythm. Contributed projects do not. They are maintained by volunteers and small vendors, they carry their own release schedules, and many sites enable a dozen or more of them. A site that patches core promptly can still run an outdated contributed module for months.
The batch also shows how a maintenance wave produces a cluster of identifiers at once. Nineteen projects published fixes on the same day, and the structured record points to 36 separate Drupal security advisories, sa-contrib-2026-154 through sa-contrib-2026-191. Operators who only watch Drupal core announcements will miss all of them.
Exposure context
A ZoomEye query on the product fingerprint returned 436,286 matching Drupal assets at the time of writing. The figure describes Drupal deployments in the index, not deployments that carry a vulnerable contributed module. Publicly reachable Drupal sites remain the pool from which an attacker has to find one that runs an unpatched extension.
What to do first
Inventory the contributed projects on every Drupal site you run, then compare each version against the fixed releases. Build the comparison from the advisory rather than from memory, because several projects shipped two fixed branches.
Stop at the highest-value targets. A module that handles authentication or API access deserves attention before a presentation-layer module, even though both appear in the same advisory.
Patch and verify
Deploy the fixed versions, then confirm the running code changed. Drupal caches aggressively, and a stale container image or an unapplied update hook leaves the vulnerable code in place while the version string looks correct.
Check the advisory pages for each project you use. Where a vendor describes a configuration that avoids the flaw, apply it until the update lands in production.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026
- CERT-BUND structured advisory record, including the product version list and referenced Drupal advisories sa-contrib-2026-154 to sa-contrib-2026-191
- ZoomEye exposure query app="Drupal", executed 24 September 2026, exact count 436286
Top comments (0)