Drupal: 25 Vulnerabilities Disclosed Together on September 2, 2026
Drupal: 25 vulnerabilities disclosed in a single batch on September 2, 2026, impacting numerous modules with severities ranging from Low to High.

Key findings
- 25 CVEs disclosed simultaneously for Drupal on September 2, 2026, spanning multiple modules.
- Vulnerabilities include Missing Authorization, XSS, LDAP Injection, and Privilege Escalation.
- Two High-severity vulnerabilities affect the Drupal Screenshot module.
- Affected modules range from Data field and LDAP integration to Blazy and Entity PDF.
- Users should consult Drupal.org/security for detailed advisories and patches.
On September 2, 2026, a significant batch of 25 vulnerabilities was disclosed for Drupal, impacting various modules and core functionalities. This coordinated disclosure event, spanning a nine-hour window, underscores the continuous need for vigilance in maintaining Drupal site security. The vulnerabilities range in severity from Low to High, with several critical issues requiring immediate attention from site administrators.
Several vulnerabilities fall into the category of "Missing Authorization" or "Incorrect Authorization," leading to "Forceful Browsing" or "Functionality Bypass." These include CVE-2026-81269 (Data field), CVE-2026-81166 (Digital Signage Framework), CVE-2026-81165 (Blazy), CVE-2026-81164 (Entity PDF), and CVE-2026-81158 (Entity API). These flaws could allow unauthorized users to access sensitive information or perform actions they should not be permitted to.
Cross-site Scripting (XSS) vulnerabilities were also prominent in this batch. CVE-2026-81201 (Monster Menus) and CVE-2026-81167 (Address Suggestion) allow for Stored XSS, enabling attackers to inject malicious scripts into web pages that are then served to other users. CVE-2026-81160 (Slick Carousel) also presents a Stored XSS risk.
Further issues include an LDAP Injection vulnerability in CVE-2026-81205 (LDAP / Active Directory Integration), which could allow attackers to manipulate LDAP queries. CVE-2026-81161 (Content Moderation Notifications) presents a Privilege Escalation risk, while CVE-2026-81159 (Commerce CyberSource) could be exploited for brute-force attacks.
Two high-severity vulnerabilities, CVE-2026-76782 and CVE-2026-76759, were disclosed for the Drupal Screenshot module. While details are sparse, their high severity rating indicates a significant risk to affected sites.
The Drupal security team has provided advisories for these vulnerabilities, with patches and updated versions available. Users are strongly encouraged to consult the official Drupal security advisories at https://www.drupal.org/security for detailed information on each CVE, affected versions, and remediation steps. Promptly applying these updates is crucial to protect Drupal websites from potential exploitation.
This large batch of disclosures highlights the dynamic nature of cybersecurity threats facing popular platforms like Drupal. Administrators must remain proactive in their security practices, regularly monitoring for and applying patches to mitigate risks associated with newly discovered vulnerabilities. Staying informed through official channels is key to maintaining a secure online presence.