For the person responsible for the site

Drupal security updates, in plain English

Drupal publishes security releases most Wednesdays, written for the developers who apply them. Every week I translate each one for the person who has to decide whether it matters: what the module does, what went wrong, who could do it, whether it applies to your site, how urgent it is, and the one line to send to whoever looks after it.

This week

Week of 7 October 2026

26 security releases · 8 rated critical or above · none for Drupal core

Rated critical or above: Block AJAX, MathJax: LaTeX for Drupal, ECA Helper, Orphans Media, Restrict route by IP, Entity Reference Manager (Merge entities) and 2 more. If your site uses any of them, start there.

Read this week's issue

A new issue every Thursday. I post the link on LinkedIn each week.

If you're new to this

What these updates are, in a minute

Most of the people I talk to have a Drupal site and have never read a security advisory. That is normal. Here is what you need to know to use these pages, and a longer version if you want it.

What a security update is

Drupal itself, which developers call core, its add on modules and its themes are all software, and software has holes. When someone finds one, the maintainers fix it, and Drupal releases the fixed version with a notice describing the hole. The notice is a security advisory. Applying the fixed version is the update, and nothing happens to your site until somebody does that.

Who publishes them

The Drupal security team, a group of volunteers from the Drupal community who coordinate the fixes and publish the advisories on drupal.org. They release on Wednesdays, which is why these pages are weekly. The team covers core, and the modules and themes whose maintainers have opted in to security coverage. A core hole affects every Drupal site at once, so a core release is always for you.

Why they matter

Once an advisory is public, it is an instruction for getting into any site that hasn't applied the fix. Depending on the hole, a stranger could read a members only page, change what your site says, or take the whole thing over. The worst Drupal holes have been used against real sites within hours of publication. Cyber Essentials expects critical and high rated fixes applied within 14 days.

What the ratings mean

The security team gives every advisory one of five ratings. The colours below are used on every page here.

  • Highly critical The worst kind. An outsider could take over the site. Fix today.
  • Critical Cyber Essentials expects a fix within 14 days. Do it this week.
  • Moderately critical Include in your next routine update, within the month.
  • Less or not critical Fix with the next routine update.

If you're not technical

You don't need to apply these yourself. You need to know who does, and to check that it happens. Ask whoever looks after your site which modules it uses and when updates were last applied. If the answer is slow or vague, that is the finding.

The longer version, with the history, what the rating checklist looks like and what to ask for, is How Drupal security updates work, in plain English.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled from the advisories published by the Drupal security team on drupal.org, most recently on 9 October 2026. The facts on each card are theirs. The plain English is mine, with help from a language model, and read before publishing.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.