Drupal Security Team Publishes 36 Contributed-Project Advisories, Including Critical Webform RCE
Security advisories published by the Drupal Security Team on 23 September 2026 cover 16 contributed projects, with 20 of the 36 public advisory pages affecting Webform. Five advisories are rated Critical, including a Webform vulnerability scored 18/25 that can result in remote code execution under a specific form configuration. Drupal core is not affected.
The disclosure adds details that were unavailable when The DropTimes covered the Security Team's advance warning. That public service announcement carried a Critical 16/25 risk score and said a widely used contributed module would receive a significant number of advisories. The released advisories identify Webform and 15 other projects, provide branch-specific fixes and show a highest disclosed score of 18/25. The advance PSA also stated that the releases it announced would not be covered by Drupal Steward.
The highest-risk issue is SA-CONTRIB-2026-175, a Critical 18/25 Webform vulnerability. Submitted data can be evaluated as template code when an affected submission is rendered, potentially leading to information disclosure, stored cross-site scripting or remote code execution. Exploitation requires a webform configured with a custom multiple-value item format containing submission-value tokens, and the Security Team rates exploitation as theoretical and the affected configuration as uncommon. Sites using Webform 6.2.x should update to 6.2.12, while sites using 6.3.x should update to 6.3.1.
The other Webform advisories cover submission access, uploaded files, temporary exports, remote imports, rendering, Webform Share, JSON:API, Entity Print and other configured features. The release notes for 6.2.12 and 6.3.1 describe 22 security fixes associated with advisories plus one additional hardening change, while Drupal.org publishes 20 Webform advisory pages dated 23 September. Those figures count different things and should not be treated as interchangeable. The advisory numbering also skips 156 and 157, so the sequence from 154 through 175 does not represent 22 consecutively published Webform advisories.
Configuration is important when assessing those Webform issues. The Webform Share advisory, for example, concerns Ajax-enabled shared forms under particular anti-spam conditions, while other advisories depend on uploaded-file settings, JSON:API responses, Entity Print, submission export or import permissions, remote URLs and configurable rendering or token behaviour.
SA-CONTRIB-2026-171 also carries the Security Team's E:Exploit risk metric. Drupal defines that value as meaning documented or deployed exploit code exists. The metric does not by itself establish that Drupal sites are currently being compromised through this vulnerability, so it should not be presented as evidence of exploitation in the wild without additional reporting.
Cloud SA-CONTRIB-2026-176 is rated Critical 15/25 and affects versions before 7.0.1. Its Kubernetes and VMware integrations did not properly validate TLS certificates when connecting to remote APIs, allowing an attacker able to intercept those connections to potentially obtain tokens or other credentials. The advisory is classified as remote code execution, while its description focuses on failed certificate validation and resulting access to credentials or connected infrastructure. Sites using private certificate authorities must configure the appropriate CA certificate path or PHP trust store after updating, then run database updates and rebuild caches.
A second Cloud advisory, SA-CONTRIB-2026-177, is also Critical 15/25 and fixed in 7.0.1. User-controlled Git branch and repository values could reach shell commands in the Kubernetes integration, allowing operating-system command execution as the web-server user. Exploitation requires the Kubernetes submodule and Git, along with permission to add or edit cloud server templates; one execution path requires additional launch permissions.
Project Browser SA-CONTRIB-2026-178 is Critical 15/25 and addresses insufficient cross-site request forgery protection for administrative actions used to enable modules or apply recipes. Sites on the 2.0.x branch should update to 2.0.3, while 2.1.x sites should use 2.1.5.
Tawk.to SA-CONTRIB-2026-184 carries a Critical 16/25 rating for a cross-site request forgery vulnerability. An attacker could induce an authenticated user to perform an unintended action through requests that were not sufficiently validated. Affected sites should update to 3.0.4 and clear Drupal's cache after the update.
The remaining affected projects also require version checks. Commerce Decoupled Checkout versions from 1.0.0 through versions before 1.8.0 should move to 8.x-1.8; sites submitting additional writable order fields must explicitly allow them and run database updates before resuming checkout. Mermaid Diagram Field versions from 1.0.4 through versions before 1.0.9 should update to 1.0.10. CookieCuttr versions from 2.0.0 through versions before 2.0.3 should update to 2.0.3.
REST & JSON API Authentication for Drupal versions before 3.2.0 should update to 3.2.0. Stop administrator login versions from 1.0 through versions before 1.6 should move to 8.x-1.6. Editoria11y Accessibility Checker requires 2.2.23 on the 2.2.x branch or 3.0.9 on the 3.0.x branch, and the Security Team also advises sites to review who has permission to run the checker.
Webform REST versions before 4.2.1 should update to 4.2.1; the 4.1.x branch is no longer supported. AI CKEditor versions before 1.4.3 should update to 1.4.3. Combined image style versions before 1.0.7 should update to 1.0.7; the advisory says sites are affected simply by having the module installed, even when no combined image styles are configured.
CSS Usage Analyzer versions from 1.0.0 through versions before 1.0.2 should update to 1.0.2. Smart Content versions before 3.2.1 should update to 3.2.1; its Smart Content Block submodule could render access-restricted blocks through an Ajax endpoint when those blocks were included in a Display Blocks reaction. Diba carousel slider users on the 3.0.x branch should update to 3.0.2, while users on 3.1.x should use 3.1.0. Sites unable to update Diba carousel slider immediately can disable the affected HTML-description option.
The batch shows why severity labels alone do not determine an individual site's exposure. Combined image style can affect a site merely because the module is installed, while several Critical issues require uncommon configurations, elevated permissions, optional integrations or specific workflows. Operators should identify affected projects in their codebase or dependency lockfile, apply the security release appropriate to each installed branch, and review the configurations and permissions identified in the relevant advisory before deployment.
Webform installations warrant a broader configuration review alongside the version update because the advisories cover multiple independent paths. Sites should review custom multiple-value formats, submission-value tokens, uploaded-file handling, Webform Share and anti-spam integration, JSON:API, Entity Print, submission exports and imports, remote URLs, handlers and submission access. Cloud installations using private certificate authorities need corresponding trust configuration, while Tawk.to requires a cache rebuild after updating.
References
-
Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175 (23 September 2026)
-
Webform - Moderately Critical - Access Bypass - SA-CONTRIB-2026-171 (23 September 2026)
-
Cloud - Critical - Remote Code Execution - SA-CONTRIB-2026-176 (23 September 2026)
-
Cloud - Critical - Remote Code Execution - SA-CONTRIB-2026-177 (23 September 2026)
-
Project Browser - Critical - Cross-Site Request Forgery - SA-CONTRIB-2026-178 (23 September 2026)
-
CookieCuttr - Moderately Critical - Cross-Site Scripting - SA-CONTRIB-2026-181 (23 September 2026)
-
Webform REST - Less Critical - Access Bypass - SA-CONTRIB-2026-186 (23 September 2026)
-
Smart Content - Moderately Critical - Access Bypass - SA-CONTRIB-2026-190 (23 September 2026)
