DEV Community

kozhevniko
kozhevniko

Posted on

Why vul.cve Returns Zero for CVE-2026-96365: Reading Exposure Data Honestly

Why vul.cve Returns Zero for CVE-2026-96365: Reading Exposure Data Honestly

Vulnerability overview

CVE-2026-96365 is one of 36 identifiers in CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026 and rated high risk. The advisory covers 16 contributed Drupal projects, with identifiers running from CVE-2026-96355 to CVE-2026-96398. Interpretation starts with the two ZoomEye results collected for this article.

Mechanism and exploitation conditions

The public record describes remote exploitation in five outcome classes: arbitrary code execution, extended privileges, bypass of security measures, data manipulation or disclosure, and cross-site scripting. It does not publish the defect behind each identifier, and that gap carries into external scanning. A scanner indexes what a service presents; a flaw in a contributed module may not present anything distinct enough to fingerprint.

Impact

CERT-BUND scores probability and damage at 4 out of 4, with a CVSS v3.1 base score of 9.8 and a temporal score of 8.5. The scanning gap does not reduce that severity. It only means external data cannot substitute for internal assessment.

Affected products and scope

The affected projects and their fixed releases are Webform 6.2.12 and 6.3.1, Webform REST 4.2.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST & JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to Live chat application 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1, and Diba carousel slider 3.0.2.

Exposure context

Two queries were run on 27 September 2026. The product query app="Drupal" returned 436403 indexed assets. The vulnerability query vul.cve="CVE-2026-96365" returned 0. The second result means the identifier is not indexed as an exposed service, which is expected for a freshly assigned CVE. Neither count identifies hosts running an affected module, and no count should be read as a victim tally.

Remediation and mitigations

Use the product count to size the population to review and the module list to scope what to check. Patch each affected module to the fixed release for its branch. Keep the two evidence types separate in reporting: what the internet shows about Drupal deployments, and what the inventory shows about modules you run.

References

Top comments (0)