Drupal patches XSS flaws in core
CERT-FR advisory details multiple XSS vulnerabilities in Drupal core affecting versions before 11.4.7, 11.3.17, and 10.6.17.
CERT-FR published an advisory summarizing a Drupal security bulletin (SA-CORE-2026-013) describing multiple cross-site scripting (XSS) vulnerabilities in Drupal core. The flaws allow an attacker to achieve indirect remote code injection via XSS, potentially enabling script execution in the context of a victim's browser session on affected Drupal sites.
Affected versions include Drupal 11.4.x prior to 11.4.7, Drupal 11.x prior to 11.3.17, and all Drupal versions prior to 10.6.17. No indication of active exploitation is mentioned in the advisory. Defenders running Drupal should apply the vendor's patches referenced in the official Drupal security bulletin as soon as possible to remediate the identified XSS issues.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1196
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free