Drupal security updates, in plain English

Week of 25 February 2026

Drupal publishes security updates on Wednesdays. This week there were 9, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 1 update

Cyber Essentials expects a fix within 14 days. Do it this week.

SAML SSO - Service Provider

Critical · 2,587 sites report using it · SA-CONTRIB-2026-018 · on drupal.org

This module allows users to log in to a website using a single sign on service.

The module does not properly clean user input. Someone could use this to uncover private details or alter existing information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate SAML SSO - Service Provider to 3.1.3.

For developers: what the fix changed

The fix sanitises the status code parameter using Xss::filter in the showErrorMessage method of src/MiniOrangeSamlAcs.php.

3.1.2 to 3.1.3 1 commit, 1 file.

  • src/MiniOrangeSamlAcs.php +5 −3 fix

Full diff, 3.1.2 to 3.1.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Moderately critical: 8 updates

Include in your next routine update, within the month.

CAPTCHA

Moderately critical · 244,414 sites report using it · SA-CONTRIB-2026-015 · on drupal.org

This module protects web forms from automated spam by requiring visitors to pass a test.

The module does not properly cancel security tokens after they are used. Someone could use this to bypass the spam protection on future form submissions. They could not view or alter any hidden information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if an attacker manually solves at least one spam test to collect valid tokens.
  • Has it been used in attacksYes. It has been used in real attacks.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate CAPTCHA to 8.x-1.17 or 2.0.10, whichever branch you are on.

For developers: what the fix changed

The fix prevents CAPTCHA replay attacks by invalidating the session token (setting it to NULL) upon successful validation in `captcha_validate()` within `captcha.module`, and prevents retrieving solutions for already solved sessions. It also regenerates the token for 'show always' persistence in `src/Element/Captcha.php`.

Also in this release The release also includes test fixes, removes the VERSION key from libraries.yml, adds a data-nosnippet attribute to the CAPTCHA template, and makes minor accessibility and logging improvements.

8.x-1.16 to 8.x-1.17 10 commits, 13 files including 6 tests.

  • .gitlab-ci.yml +2 −2
  • captcha.inc +4 −0
  • captcha.module +37 −29 fix
  • modules/image_captcha/image_captcha.libraries.yml +0 −3
  • modules/image_captcha/js/image_captcha_refresh.js +1 −1
  • src/Element/Captcha.php +15 −0 fix
  • templates/captcha.html.twig +11 −9

Full diff, 8.x-1.16 to 8.x-1.17 · Full diff, 2.0.9 to 2.0.10

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Tagify

Moderately critical · 21,452 sites report using it · SA-CONTRIB-2026-013 · on drupal.org

This module improves the interface for selecting categories on a website.

The module does not properly clean user input before displaying it. Someone could use this to run malicious scripts in the browser when creating or editing a piece of content. They could uncover private details and manipulate website records.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Tagify to 1.2.49.

For developers: what the fix changed

The fix sanitises user input by wrapping variables with Drupal.checkPlain in js/tagify.js. This prevents arbitrary JavaScript execution by escaping values in functions such as highlightMatchingLetters, entityIdMarkup, and tagTemplate.

1.2.48 to 1.2.49 1 commit, 1 file.

  • js/tagify.js +17 −12 fix

Full diff, 1.2.48 to 1.2.49

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Drupal Canvas

Moderately critical · 11,747 sites report using it · SA-CONTRIB-2026-017 · on drupal.org

This module allows people to design and build a website directly in their browser.

The module does not properly clean data sent in certain requests. Someone could use this to discover hidden system details. They could not alter any information.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if the hidden artificial intelligence sub module is enabled and an attacker has an account with the access right to use it.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal Canvas to 1.1.1.

For developers: what the fix changed

The fix updates CanvasBuilder.php to strictly validate that the provided file source is a base64 encoded JPEG or PNG data URI and uses base64_decode instead of file_get_contents, preventing server side request forgery.

1.1.0 to 1.1.1 1 commit, 1 file.

  • modules/canvas_ai/src/Controller/CanvasBuilder.php +3 −4 fix

Full diff, 1.1.0 to 1.1.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Responsive Favicons

Moderately critical · 10,758 sites report using it · SA-CONTRIB-2026-019 · on drupal.org

This module adds browser tab icons generated by an external service to a website.

The module does not filter text entered by an administrator. Someone could use this to view restricted information or modify website records.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youA site is affected if an attacker has an account with the access right to administer responsive favicons.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Responsive Favicons to 2.0.2.

For developers: what the fix changed

The fix adds the restrict access flag to the administer responsive favicons permission in responsive_favicons.permissions.yml to mitigate the cross site scripting vulnerability by warning that the permission is for trusted users only.

2.0.1 to 2.0.2 1 commit, 1 file.

  • responsive_favicons.permissions.yml +1 −0 fix

Full diff, 2.0.1 to 2.0.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Anti-Spam by CleanTalk

Moderately critical · 6,783 sites report using it · SA-CONTRIB-2026-014 · on drupal.org

This module blocks automated bots using a firewall.

The module does not properly clean user input. Someone could use this to reveal protected information or manipulate website content.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if a visitor is challenged or blocked by the firewall.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Anti-Spam by CleanTalk to 9.7.0.

For developers: what the fix changed

The fix sanitises the `$request_uri` variable using `htmlspecialchars` in `lib/Cleantalk/Common/Firewall/Modules/Sfw.php` to prevent reflected XSS when users are challenged by the firewall.

Also in this release The release also includes fixes for duplicated cookie settings, PostgreSQL database support improvements, and various code formatting updates.

9.6.1 to 9.7.0 35 commits, 43 files including 1 test.

  • .gitlab-ci.yml +2 −1
  • cleantalk.module +19 −5
  • composer.json +2 −2
  • js/apbct-public.js +7 −1
  • lib/Cleantalk/Common/Antispam/Cleantalk.php +13 −0
  • lib/Cleantalk/Common/Db/Db.php +138 −138
  • lib/Cleantalk/Common/Db/DbTablesCreator.php +7 −7
  • lib/Cleantalk/Common/Firewall/FirewallUpdater.php +132 −21
  • lib/Cleantalk/Common/Firewall/Modules/AntiCrawler.php +16 −4
  • lib/Cleantalk/Common/Firewall/Modules/Sfw.php +6 −4 fix
  • lib/Cleantalk/Common/Helper/Helper.php +2 −2
  • lib/Cleantalk/Common/Http/Request.php +4 −8

Full diff, 9.6.1 to 9.7.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Material Icons

Moderately critical · 2,790 sites report using it · SA-CONTRIB-2026-011 · on drupal.org

This module allows users to add icons to the text editor.

The module does not properly check access rights for certain pages. Someone could use this to access features they should not reach. They could not view protected information but they could manipulate website content.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Material Icons to 2.0.4.

For developers: what the fix changed

The fix adds a new permission in material_icons.permissions.yml and updates material_icons.routing.yml to require this permission for the dialog and autocomplete routes instead of the generic access content permission.

Also in this release The release also adds sanitisation and validation to the submitted form values in src/Form/IconDialog.php.

2.0.3 to 2.0.4 1 commit, 3 files.

  • material_icons.permissions.yml +4 −0 fix
  • material_icons.routing.yml +2 −2 fix
  • src/Form/IconDialog.php +9 −3

Full diff, 2.0.3 to 2.0.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Islandora

Moderately critical · 726 sites report using it · SA-CONTRIB-2026-016 · on drupal.org

This module connects a website to an open source digital asset management system.

The module does not properly clean web addresses used for attaching media to a piece of content. Someone could use this to access private files or modify website records.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if an attacker has an account with the access right to create media and the ability to edit the piece of content the media is attached to.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Islandora to 2.17.5.

For developers: what the fix changed

The fix adds a `validateContentLocation` method in `src/MediaSource/MediaSourceService.php` to sanitize the `Content-Location` header, preventing path traversal and ensuring it is a valid stream wrapper URI. It also introduces `determinePersistedMimeType` to securely guess the MIME type of uploaded files instead of trusting user input.

Also in this release Added automated tests to verify the new path traversal and MIME-type spoofing protections.

2.17.4 to 2.17.5 1 commit, 3 files including 1 test.

  • islandora.services.yml +1 −1 fix
  • src/MediaSource/MediaSourceService.php +93 −3 fix

Full diff, 2.17.4 to 2.17.5

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Theme Negotiation by Rules

Moderately critical · 129 sites report using it · SA-CONTRIB-2026-012 · on drupal.org

This module allows a website to display pages with different designs based on specific conditions.

The module uses insecure web requests to turn design rules on or off. Someone could trick an administrator into clicking a link to change these rules. They could not view private details but they could alter website settings.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if an attacker knows the internal system name of a design rule.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Theme Negotiation by Rules to 1.2.1.

For developers: what the fix changed

Adds CSRF token requirements to the enable and disable routes in theme_rule.routing.yml.

1.2.0 to 1.2.1 1 commit, 1 file.

  • theme_rule.routing.yml +2 −0 fix

Full diff, 1.2.0 to 1.2.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.