Which Drupal Modules an Automated Scanner Hits First After WID-SEC-2026-3554
Vulnerability overview
WID-SEC-2026-3554, published by CERT-BUND on 23 September 2026 and rated high risk, bundles 36 identifiers from CVE-2026-96355 to CVE-2026-96398. CVE-2026-96359 is one of them. All of them concern contributed Drupal projects.
The affected set covers Webform, Webform REST, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST & JSON API Authentication, Stop administrator login, Tawk.to Live chat application, Editoria11y Accessibility Checker, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider. The record scores the batch at CVSS v3.1 base 98 and temporal 85.
Which modules a scanner reaches first
Public advisories do not stay quiet for long. Once a batch like this is published, automated scanning follows, and scanners do not read your architecture diagram. They probe paths that are reachable without credentials and cheap to test.
That reorders the practical risk. REST & JSON API Authentication exposes endpoints that exist for programmatic access, which is exactly the kind of surface a scanner enumerates without a session. Webform and Webform REST accept anonymous submissions by design on most public sites, so their routes are known and reachable. Stop administrator login changes how administrative access is granted, and any weakness in that logic sits on a path attackers already probe.
Everything else in the list still matters, but it usually needs either an authenticated session, a specific page view, or a configuration that exposes the component. That is a real difference in exposure timeline, not in severity.
Module-by-module reachability
Group the batch by how a request reaches the code.
Open, anonymous reachability: Webform, Webform REST, REST & JSON API Authentication.
Access-control adjacent: Stop administrator login.
Stored or rendered content: Smart Content, Editoria11y Accessibility Checker, AI CKEditor, Mermaid Diagram Field, Combined image style, CSS Usage Analyzer.
Feature and integration modules: Cloud, Commerce Decoupled Checkout, Project Browser, Tawk.to Live chat application, CookieCuttr, Diba carousel slider.
CERT-BUND does not publish this grouping. It follows from how these projects are normally deployed, and it should be revised the moment a project advisory assigns a concrete route to a specific CVE.
Affected versions
Fixed releases are Webform 6.2.12 and 6.3.1, Webform REST 4.2.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST & JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to Live chat application 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1, and Diba carousel slider 3.0.2. Drupal core is outside the advisory.
Exposure context
A query for app="Drupal" on 26 September 2026 returned 436,359 assets; a query for vul.cve="CVE-2026-96359" returned zero.
The first figure shows how many Drupal deployments are indexed and therefore how many candidates a scanner can work through. It does not indicate how many run an affected module. The second shows only that this CVE is not indexed as an exposed service.
Mitigation
Patch in the order above rather than alphabetically. Watch request logs for the affected projects' routes, and treat unusual parameters against them as the first signal. Where a module cannot be updated, disable it so its routes leave the request cycle.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026, high risk
- CERT-BUND structured advisory record with affected and fixed versions
- ZoomEye search app="Drupal", executed 26 September 2026, exact count 436359
Top comments (0)