Why moderately critical advisories like CVE-2026-96360 get postponed
Vulnerability overview
SA-CONTRIB-2026-154 for CVE-2026-96360 was published by Drupal on 2026-September-23. It covers the Webform contributed module and carries Drupal’s Moderately critical label with a score of 11 out of 25 and the vector AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon.
The triage pattern that creates risk
When a release round mixes critical and moderate advisories, the moderate ones tend to wait. The label suggests less urgency, and the patch often lands after the critical items that consumed the maintenance window. What that reasoning misses is that the moderate advisory usually has simpler preconditions and a wider population of affected sites than the critical one that overshadowed it.
Mechanism and exploitation conditions
Webform announces dynamic form updates to assistive technologies. The announcement text is not sanitised sufficiently, so it can be interpreted as markup rather than as text. Exploitation requires administrative permissions on the affected site, and the required target distribution is uncommon, which is part of why the issue is rated moderate rather than critical.
Impact
Script executes in the session of a user interacting with the affected form. Confidentiality and integrity are rated Some and availability is unaffected. If the interacting user holds administrative permissions, the blast radius grows to content and configuration changes.
Affected products and scope
The affected product is the Webform contributed module for Drupal, machine name webform. The same release round carried advisories for other contributed projects, including a critical remote code execution issue in the same module.
Remediation and mitigations
Treat every advisory in a release round as part of one deployment. Update Webform and the other affected contributed modules, verify versions from the site report, and clear caches. Reduce the number of administrative accounts so that the precondition behind the flaw is rarer. Schedule routine inventory reviews so that a postponed moderate advisory has a deadline rather than an intention.
Exposure context
A ZoomEye CVE query for vul.cve="CVE-2026-96360" returned 0 on 2026-09-26, and a product query for app="Drupal" returned 436368. The zero reflects indexing rather than safety, and the product count describes general Drupal deployments.
References
Drupal security advisories, SA-CONTRIB-2026-154, https://www.drupal.org/security. CERT-Bund advisory WID-SEC-2026-3554, https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554.