Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem The distinction that matters Drupal security advisory SA-CONTRIB-2026-161, published 23 September 2026, covers CVE-2026-96363 and the affected project is Webform, a contributed module. The affected code path is Webform Entity...

Source: [Dev.to](https://dev.to/bianliang/why-cve-2026-96363-is-the-submodule-problem-not-a-drupal-core-problem-6bc)

Sponsored