CVE-2026-96361 in Context: How This Drupal Batch Compares with Core Security Releases
Vulnerability overview
CVE-2026-96361 is one of 36 identifiers in CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and rated high risk. The advisory names 16 contributed Drupal projects and its identifiers run from CVE-2026-96355 to CVE-2026-96398.
Placing the batch next to Drupal core releases clarifies what operators are dealing with.
Mechanism and exploitation conditions
The record describes remote exploitation and confirms that patches exist. Its outcome classes are arbitrary code execution, extended privileges, bypass of security measures, data manipulation or disclosure, and cross-site scripting. It does not publish a per-identifier mechanism statement.
The structural difference from a core release is ownership. Core security releases arrive on a published cadence with a support window behind them. Contributed projects follow their own maintainer schedules, and the batch shows that difference: 19 fixed releases were needed to cover 16 projects.
Impact
The batch carries damage and probability of 4 out of 4 and a CVSS v3.1 base score of 9.8 with a temporal score of 8.5. Those figures describe the severity of the affected code paths rather than a confirmed exploitation campaign, which the record does not report.
Affected products and scope
The 16 projects are Webform, Webform REST, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST & JSON API Authentication, Stop administrator login, Tawk.to Live chat application, Editoria11y Accessibility Checker, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content, and Diba carousel slider. Fixed releases run from Webform 6.2.12 and 6.3.1 through Diba carousel slider 3.0.2. Core is excluded from the advisory.
Exposure context
ZoomEye returned 436,344 assets for app="Drupal" on 26 September 2026, which counts Drupal deployments rather than sites running a listed module. A query for vul.cve="CVE-2026-96361" returned 0, so the identifier is not indexed as an exposed service.
Remediation and mitigations
Treat contributed modules as a separate maintenance track from core. Track which projects in your estate still ship security releases, apply the fixed release for each affected one, and remove modules that no longer receive fixes. Where a project published two fixed releases, record which branch you run so the next advisory resolves faster.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026
- CERT-BUND structured record for WID-SEC-2026-3554, 16 projects and 19 fixed releases
- ZoomEye search app="Drupal", executed 26 September 2026, exact count 436344
Top comments (0)