[NEW] [UNPATCHED] [high] Drupal Module: Multiple vulnerabilities enable unspecified attack
An attacker can exploit multiple vulnerabilities in various Drupal extensions to perform an unspecified attack.
CSIRTS triage
- What
- Multiple unspecified Drupal extensions contain vulnerabilities enabling unspecified attacks; patch status is not available.
- Who is affected
- Drupal installations with affected extensions are vulnerable to unspecified attack vectors.
- Urgency
- High urgency; unpatched status and high severity rating indicate these vulnerabilities remain exploitable with no immediate fix.
- Action
- Monitor Drupal security advisories for patch availability and disable or replace affected extensions until patches are released.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Drupal Module
Get an email when a new Drupal Module advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2943
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-76755 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76756 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76757 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76758 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76759 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76782 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-76782: Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.nvd
- highCVE-2026-76759: Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.nvd
- mediumCVE-2026-76758: Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: …nvd
- mediumCVE-2026-76757: Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.nvd
- mediumCVE-2026-76756: Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.nvd
- mediumCVE-2026-76755: Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.nvd
Recent advisories for Drupal Module
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Drupal Module: Multiple vulnerabilitiescert-bund · 2026-09-03
- medium[NEW] [medium] Drupal Module: Multiple Vulnerabilitiescert-bund · 2026-09-03
- medium[NEW] [medium] Drupal Modules: Multiple Vulnerabilitiescert-bund · 2026-08-26
- high[NEW] [high] Drupal Modules: Multiple vulnerabilitiescert-bund · 2026-07-23
- high[UPDATE] [high] Drupal Modules: Multiple vulnerabilities allow data manipulationcert-bund · 2026-07-13
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Langflow: Multiple vulnerabilities2026-09-04
- medium[NEW] [medium] Grafana Enterprise: Multiple vulnerabilities allow gaining user or administrator privileges2026-09-04
- low[NEW] [low] Checkmk: Vulnerability allows Denial of Service2026-09-04
- low[NEW] [low] ImageMagick: Multiple vulnerabilities allow Denial of Service2026-09-04
- critical[NEW] [critical] vm2: Multiple vulnerabilities allow code execution2026-09-04