Drupal security updates, in plain English

Week of 20 May 2026

Drupal publishes security updates on Wednesdays. This week there was one, for Drupal core itself.

One is for Drupal core. That applies to every Drupal site, so start there.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Highly critical: 1 update

The worst kind. An outsider could take over the site. Fix today.

Drupal core

Highly critical · Drupal core · every Drupal site · SA-CORE-2026-004 · on drupal.org

This is the underlying software that runs the entire website and manages all the content.

A flaw allows anyone on the internet to view any private information stored in the website database. They could also alter any content or add their own computer code to take over the system.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected by the main flaw if it uses a PostgreSQL database, and it might be affected by other underlying software flaws depending on its setup and extra features.
  • Has it been used in attacksYes. It has been used in real attacks.
  • How urgentDrupal rates this highly critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Drupal core to 10.6.9, 11.3.10, 10.5.10, 10.4.10 or 11.2.12, whichever branch you are on.

For developers: what the fix changed

The fix prevents SQL injection by ensuring that array values in SQL conditions are re-indexed using `array_values()` in `Condition::compile`, `ConditionAggregate::compile`, and the PostgreSQL-specific `Condition::translateCondition`, which stops malicious associative array keys from being injected into the query.

Also in this release The release also updated Symfony, Twig, and Underscore.js dependencies, and bumped the Drupal core version to 10.6.9.

10.6.8 to 10.6.9 4 commits, 19 files.

  • composer.json +1 −1
  • composer.lock +0 −0
  • composer/Metapackage/CoreRecommended/composer.json +32 −32
  • composer/Metapackage/DevDependencies/composer.json +1 −1
  • composer/Metapackage/PinnedDevDependencies/composer.json +9 −9
  • core/assets/vendor/underscore/underscore-min.js +0 −0
  • core/assets/vendor/underscore/underscore-min.js.map +0 −0
  • core/composer.json +6 −6
  • core/core.libraries.yml +2 −2
  • core/lib/Drupal.php +1 −1
  • core/lib/Drupal/Component/DependencyInjection/composer.json +1 −1
  • core/lib/Drupal/Component/EventDispatcher/composer.json +1 −1

Full diff, 10.6.8 to 10.6.9 · Full diff, 11.3.9 to 11.3.10 · Full diff, 10.5.9 to 10.5.10 · Full diff, 10.4.9 to 10.4.10 · Full diff, 11.2.11 to 11.2.12

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.