Drupal security updates, in plain English

Week of 17 June 2026

Drupal publishes security updates on Wednesdays. This week there were 4: 1 for Drupal core itself and 3 for modules. Between them they carry 8 security fixes, because a module can fix several bugs in one update: Drupal core fixed 5.

One is for Drupal core. That applies to every Drupal site, so start there.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 4 updates

Cyber Essentials expects a fix within 14 days. Do it this week.

Formatter Field

Critical · 419 sites report using it · SA-CONTRIB-2026-048 · on drupal.org

This module provides a way to choose how specific fields are displayed on individual pieces of content.

An ordinary account on the site could write malicious data directly into a display settings field. This could allow them to view or alter any information on the site including the underlying code.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if a person has access rights to edit a piece of content with a display settings field and the site allows full edit access through a data feed or another direct method.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Formatter Field to 2.0.0.

For developers: what the fix changed

The fix updates calls to `unserialize()` in `DefaultFormatter.php`, `FromFieldFormatter.php`, and `FormatterWidget.php` to include `['allowed_classes' => FALSE]`, preventing object injection. It also changes `#markup` to `#plain_text` when rendering settings in `DefaultFormatter.php`.

Also in this release Added compatibility for Drupal 9, 10, and 11, introduced GitLab CI configuration, fixed coding standards, and modernised the README file.

8.x-1.1 to 2.0.0 9 commits, 11 files.

  • .cspell-project-words.txt +5 −0
  • .gitlab-ci.yml +104 −0
  • README.md +44 −0
  • config/schema/formatter_field.schema.yml +2 −2
  • formatter_field.info.yml +1 −1
  • formatter_field.module +1 −1
  • readme.txt +0 −24
  • src/Plugin/Field/FieldFormatter/DefaultFormatter.php +5 −5 fix
  • src/Plugin/Field/FieldFormatter/FromFieldFormatter.php +3 −3 fix
  • src/Plugin/Field/FieldType/FormatterItem.php +9 −6
  • src/Plugin/Field/FieldWidget/FormatterWidget.php +8 −7 fix

Full diff, 8.x-1.1 to 2.0.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Plotly.js Graphing

Critical · 46 sites report using it · SA-CONTRIB-2026-050 · on drupal.org

This module provides a way to create and display custom graphs and charts.

An ordinary account on the site could write malicious data directly into a graph field. This could allow them to view or alter any information on the site including the underlying code.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if a person has access rights to edit a piece of content with a graph field and the site allows full edit access through a data feed or another direct method.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Plotly.js Graphing to 3.0.2 or 4.0.0, whichever branch you are on.

For developers: what the fix changed

The fix prevents object injection by passing an array with allowed classes set to false to the unserialize function in PlotlyJsGraphFormatter.php and PlotlyJsGraphWidget.php. It also adds the serialized property names annotation to the PlotlyJsGraph field type in PlotlyJsGraph.php.

Also in this release Added a Drush 9 command to download the Plotly.js library and updated the README file.

3.0.1 to 3.0.2 2 commits, 6 files.

  • README.md +2 −2
  • drush.services.yml +8 −0
  • src/Commands/PlotlyJsCommands.php +68 −0
  • src/Plugin/Field/FieldFormatter/PlotlyJsGraphFormatter.php +2 −2 fix
  • src/Plugin/Field/FieldType/PlotlyJsGraph.php +4 −0 fix
  • src/Plugin/Field/FieldWidget/PlotlyJsGraphWidget.php +2 −2 fix

Full diff, 3.0.1 to 3.0.2 · Full diff, 3.0.2 to 4.0.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Drupal core

Critical · Drupal core · every Drupal site · 5 security fixes

This software provides the foundation for building and managing a website.

5 security fixes in one update. Drupal core fixed 5 separate security bugs this week: 1 php object injection, 1 improper validation, 1 server side request forgery, 1 gadget chain, 1 cache poisoning and open redirect. One update covers all of them. The most serious, SA-CORE-2026-005, is explained here and the full list is at the end of the card.

An ordinary account on the site could inject malicious code through a data feed. This could allow them to view or alter any information on the site including the underlying code.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if it uses a specific type of reference field and allows write access through a data feed.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Drupal core to 11.3.12, 10.6.11, 11.2.14, 10.5.12 or 11.4.0-rc2, whichever branch you are on.

For developers: what the fix changed

This release carries 5 security fixes. The summary below is for SA-CORE-2026-005, the most serious of them.

The fix prevents PHP object injection by disabling class instantiation during unserialisation in PrimitiveDataNormalizer::doNormalize and by rejecting serialised string values for relationship meta fields in EntityResource::addToRelationshipData and EntityResource::doPatchMultipleRelationship.

Also in this release The release also includes fixes for several other security advisories, updating Guzzle dependencies, adding trusted host checks for oEmbed discovery and rebuild scripts, and improving file upload validation for images.

11.3.11 to 11.3.12 7 commits, 15 files including 1 test.

  • composer.lock +16 −15
  • composer/Metapackage/CoreRecommended/composer.json +2 −2
  • composer/Metapackage/PinnedDevDependencies/composer.json +1 −1
  • core/assets/scaffold/files/default.settings.php +17 −0
  • core/composer.json +1 −1
  • core/lib/Drupal.php +1 −1
  • core/lib/Drupal/Component/Datetime/DateTimePlus.php +1 −3
  • core/modules/file/src/Plugin/rest/resource/FileUploadResource.php +5 −0
  • core/modules/jsonapi/src/Controller/EntityResource.php +29 −3 fix
  • core/modules/jsonapi/src/Controller/FileUpload.php +4 −0
  • core/modules/media/src/OEmbed/UrlResolver.php +17 −0
  • core/modules/serialization/src/Normalizer/PrimitiveDataNormalizer.php +1 −1 fix

Full diff, 11.3.11 to 11.3.12 · Full diff, 10.6.10 to 10.6.11 · Full diff, 11.2.13 to 11.2.14 · Full diff, 10.5.11 to 10.5.12 · Full diff, 11.3.18 to 11.4.0-rc2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 5 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Flag attendance field

Critical · no install count published · SA-CONTRIB-2026-049 · on drupal.org

This module provides a way to track attendance for events or classes.

An ordinary account on the site could write malicious data directly into an attendance field. This could allow them to view or alter any information on the site including the underlying code.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if a person has access rights to edit a piece of content with an attendance field and the site allows full edit access through a data feed or another direct method.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Flag attendance field to 8.x-1.2.

For developers: what the fix changed

The fix prevents PHP object injection by passing an array with allowed_classes set to false as the second argument to unserialize in FlagAttendanceFormatter.php and FlagAttendanceWidget.php.

8.x-1.1 to 8.x-1.2 1 commit, 2 files.

  • src/Plugin/Field/FieldFormatter/FlagAttendanceFormatter.php +1 −1 fix
  • src/Plugin/Field/FieldWidget/FlagAttendanceWidget.php +1 −1 fix

Full diff, 8.x-1.1 to 8.x-1.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.