Drupal Security Updates – 15 July 2026

Drupal has released security updates to address several vulnerabilities affecting multiple Drupal products.

The addressed vulnerabilities could allow the attacker to perform cross-site scripting (XSS), path traversal, and SQL injection attacks, gain elevated privileges, bypass security restrictions, obtain sensitive information, or execute arbitrary code on the affected system, potentially leading to full compromise.

Sample of the addressed vulnerabilities:

1. Drupal AlternativeCommerce Code Execution Vulnerability (CVE-2026-9726):

  • CVSS Score: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Remote Code Execution

2. Drupal LocalGov Workflows Information Disclosure Vulnerability (CVE-2026-10768):

  • CVSS Score: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

Sample of the affected products:

  • Drupal Commerce.
  • Drupal Clean RESTful.
  • Drupal Drupal Canvas.
  • Drupal Drupal AlternativeCommerce Basket.
  • Drupal Siteimprove Analytics.
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Drupal Security Updates

References