CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73476

mediumcovered by 1 sourcefirst seen 2026-08-13
An attacker can exploit multiple vulnerabilities in Drupal to disclose information, manipulate data and bypass security measures.

CSIRTS triage

What
Multiple vulnerabilities in Drupal allow attackers to disclose information, manipulate data, and bypass security measures.
Who is affected
Drupal deployments of unspecified versions are affected.
Urgency
Medium urgency; not currently exploited in the wild, but multiple attack vectors present a moderate risk.
Action
Update Drupal to the latest patched version addressing CVE-2026-73474 through CVE-2026-73478.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-73476

Get an email if CVE-2026-73476 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-73476

CVE.org record

Embed the live status

CVE-2026-73476 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73476 status](https://www.csirts.com/badge/CVE-2026-73476)](https://www.csirts.com/cve/CVE-2026-73476)