Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem The distinction that matters Drupal security advisory SA-CONTRIB-2026-161, published 23 September 2026, covers CVE-2026-96363 and the affected project is Webform, a contributed module. The affected code path is Webform Entity Print, a submodule that ships inside the Webform project. Drupal core is not named as affected. That distinction is practical. Core vulnerabilities trigger site-wide emergency processes...