VENDOR

Drupal vulnerabilities: CVEs, exploitation and patches

Every Drupal CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-73475
    Commerce PayPal forceful browsing lets unauthenticated users access Drupal Commerce PayPal ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  2. CVE-2026-16639
    Internationalization Single Sign-On authentication bypass Drupal Internationalization Single Sign-On ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-16641 CRITICAL 9.8
3 CVEs · page 1 of 1