For the person responsible for the site
Drupal security updates, in plain English
Drupal publishes security releases most Wednesdays, written for the developers who apply them. Every week I translate each one for the person who has to decide whether it matters: what the module does, what went wrong, who could do it, whether it applies to your site, how urgent it is, and the one line to send to whoever looks after it.
This week
Week of 7 October 2026
Rated critical or above: Block AJAX, MathJax: LaTeX for Drupal, ECA Helper, Orphans Media, Restrict route by IP, Entity Reference Manager (Merge entities) and 2 more. If your site uses any of them, start there.
Read this week's issueA new issue every Thursday. I post the link on LinkedIn each week.
Find a module
Has something your site uses had a security release?
Type the name of a module or theme, or type "core" for Drupal itself. This searches every release covered here since 7 October 2026, across every week, and links to the card for each one.
Type at least two letters, or pick a rating to see everything at that level.
Don't know which modules and theme your site uses? That is the first question to ask whoever looks after it. Or browse every module and theme that has had a release, most widely used first.
If you're new to this
What these updates are, in a minute
Most of the people I talk to have a Drupal site and have never read a security advisory. That is normal. Here is what you need to know to use these pages, and a longer version if you want it.
What a security update is
Drupal itself, which developers call core, its add on modules and its themes are all software, and software has holes. When someone finds one, the maintainers fix it, and Drupal releases the fixed version with a notice describing the hole. The notice is a security advisory. Applying the fixed version is the update, and nothing happens to your site until somebody does that.
Who publishes them
The Drupal security team, a group of volunteers from the Drupal community who coordinate the fixes and publish the advisories on drupal.org. They release on Wednesdays, which is why these pages are weekly. The team covers core, and the modules and themes whose maintainers have opted in to security coverage. A core hole affects every Drupal site at once, so a core release is always for you.
Why they matter
Once an advisory is public, it is an instruction for getting into any site that hasn't applied the fix. Depending on the hole, a stranger could read a members only page, change what your site says, or take the whole thing over. The worst Drupal holes have been used against real sites within hours of publication. Cyber Essentials expects critical and high rated fixes applied within 14 days.
What the ratings mean
The security team gives every advisory one of five ratings. The colours below are used on every page here.
If you're not technical
You don't need to apply these yourself. You need to know who does, and to check that it happens. Ask whoever looks after your site which modules it uses and when updates were last applied. If the answer is slow or vague, that is the finding.
The longer version, with the history, what the rating checklist looks like and what to ask for, is How Drupal security updates work, in plain English.
Not sure what your site is running?
Send me your Drupal site's address.
I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk