Drupal security advisory (AV26-738)
Serial number: AV26-738 Date: July 22, 2026 On July 22, 2026, Drupal published security advisories to address a vulnerability in the following product. Included was a critical update for the following: Internationalization Single Sign-On – versions prior to 1.8.0 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations. Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 Drupal Security Advisories
CSIRTS triage
- What
- A critical access bypass vulnerability has been identified.
- Who is affected
- Users of Internationalization Single Sign-On versions prior to 1.8.0.
- Urgency
- Remediation is important as it is a critical vulnerability.
- Action
- Apply the necessary updates or perform the suggested mitigations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Internationalization Single Sign-On
Get an email when a new Internationalization Single Sign-On advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/drupal-security-advisory-av26-738
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30