Drupal security updates, in plain English

Week of 10 June 2026

Drupal publishes security updates on Wednesdays. This week there were 5, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 3 updates

Cyber Essentials expects a fix within 14 days. Do it this week.

Mother May I

Critical · 101 sites report using it · SA-CONTRIB-2026-045 · on drupal.org

This module manages access rights for users on the website.

This project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Mother May I. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Brute force attack protection

Critical · 2 sites report using it · SA-CONTRIB-2026-047 · on drupal.org

This module protects the website from automated systems guessing user passwords.

This project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Brute force attack protection. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Composer

Critical · no install count published · SA-CONTRIB-2026-046 · on drupal.org

This module connects the website to a software management tool.

This project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Composer. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Moderately critical: 2 updates

Include in your next routine update, within the month.

Tagify

Moderately critical · 21,452 sites report using it · SA-CONTRIB-2026-043 · on drupal.org

This module provides a dropdown menu to help users select categories when filling out forms.

A flaw in the dropdown menu allows scripts to be hidden inside the names of parent categories. Someone could run these scripts in the browser of another user to view private information or make unauthorised changes. They could not take full control of the website.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if the site gives users the access right to create or edit categories.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Tagify to 1.2.52.

For developers: what the fix changed

The fix sanitises parent taxonomy term names by wrapping `parentName` with `Drupal.checkPlain()` when generating the dropdown HTML in `js/tagify.js`. It also updates the `highlightMatchingLetters` function to escape segments individually, preventing HTML-entity corruption.

Also in this release The release also fixes `maxItems` handling in the facets widget and removes a broken Sortable dependency.

1.2.51 to 1.2.52 5 commits, 3 files.

  • js/tagify.js +47 −50 fix
  • modules/tagify_facets/js/tagify-widget.js +3 −12
  • modules/tagify_facets/tagify_facets.libraries.yml +0 −1

Full diff, 1.2.51 to 1.2.52

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Examples for Developers

Moderately critical · 797 sites report using it · SA-CONTRIB-2026-044 · on drupal.org

This module provides sample code to help programmers build new features for the website.

A flaw in the file reading feature allows someone to view any file on the server. They could read private files and they could also change or add some data. They could not take full control of the website.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youThis applies if the site uses the file example part of the module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Examples for Developers to 4.0.6.

For developers: what the fix changed

The fix removes the vulnerable file_example submodule entirely, deleting all its files and removing its route from the _examples_toolbar_routes function in examples.module.

4.0.5 to 4.0.6 2 commits, 14 files including 1 test.

  • examples.module +0 −1 fix
  • modules/file_example/file_example.info.yml +0 −9 fix
  • modules/file_example/file_example.links.menu.yml +0 −5 fix
  • modules/file_example/file_example.module +0 −98 fix
  • modules/file_example/file_example.permissions.yml +0 −11 fix
  • modules/file_example/file_example.routing.yml +0 −8 fix
  • modules/file_example/file_example.services.yml +0 −13 fix
  • modules/file_example/src/FileExampleFileHelper.php +0 −117 fix
  • modules/file_example/src/FileExampleSessionHelperWrapper.php +0 −37 fix
  • modules/file_example/src/FileExampleStateHelper.php +0 −73 fix
  • modules/file_example/src/FileExampleSubmitHandlerHelper.php +0 −518 fix
  • modules/file_example/src/Form/FileExampleReadWriteForm.php +0 −206 fix

Full diff, 4.0.5 to 4.0.6

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.