Drupal security updates, in plain English

Week of 9 September 2026

Drupal publishes security updates on Wednesdays. This week there were 10, all for modules. Between them they carry 20 security fixes, because a module can fix several bugs in one update: SAML SSO - Service Provider fixed 11.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 6 updates

Cyber Essentials expects a fix within 14 days. Do it this week.

amazee.ai Private AI Provider

Critical · 8,283 sites report using it · SA-CONTRIB-2026-134 · on drupal.org

This module connects the website to artificial intelligence services and provides a database for intelligent search features.

The module does not properly clean up search filters before using them to query the database. Anyone visiting the site could run malicious database commands to read any private information and change some data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if it uses the module for intelligent search and exposes a specific type of search filter to visitors.
  • Has it been used in attacksA working example has been published, so assume someone will try.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate amazee.ai Private AI Provider to 1.3.7 or 1.4.3, whichever branch you are on.

For developers: what the fix changed

The fix updates `PostgresProvider.php` to quote all Search API filter values using `prepareStringArrayForSql` regardless of their field type, preventing SQL injection. It also removes the insecure `prepareArrayForSql` method from `PostgresPgvectorClient.php`.

Also in this release The release also fixes an issue where key provisioning requests would time out and retry by increasing the timeout and disabling retries.

1.3.6 to 1.3.7 2 commits, 5 files including 2 tests.

  • src/AmazeeIoApi/AmazeeClient.php +8 −3
  • src/Vdb/Postgres/Plugin/VdbProvider/PostgresProvider.php +3 −8 fix
  • src/Vdb/Postgres/PostgresPgvectorClient.php +0 −14 fix

Full diff, 1.3.6 to 1.3.7 · Full diff, 1.4.2 to 1.4.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

CSP log

Critical · 3,258 sites report using it · SA-CONTRIB-2026-136 · on drupal.org

This module collects and displays reports about security policy errors on the website.

The module does not properly clean up user input before using it to search the database. An administrator could run malicious database commands to read any private information and change some data.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youA site is affected if an attacker has the access right to view the security reports.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate CSP log to 1.0.2.

For developers: what the fix changed

The fix updates the database query in src/CspLogService.php to use parameterised queries and integer casting for the minimum and maximum amount filters instead of concatenating them directly into the having clause.

Also in this release The release also fixes a bug where the maximum amount filter was incorrectly using the date filter value.

1.0.1 to 1.0.2 1 commit, 1 file.

  • src/CspLogService.php +2 −2 fix

Full diff, 1.0.1 to 1.0.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

SAML SSO - Service Provider

Critical · 2,587 sites report using it · 11 security fixes

This module lets users log into the website using an external identity provider like Google or Microsoft.

11 security fixes in one update. SAML SSO - Service Provider fixed 11 separate security bugs this week: 2 cross site scripting, 1 weak cryptographic practices, 1 open redirect, 1 improper certificate validation, 1 improper access control, 1 server side request forgery, 1 insufficient replay protection, 1 information disclosure, 1 embedded credentials, 1 authentication bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-144, is explained here and the full list is at the end of the card.

The module uses outdated methods for generating random numbers and checking digital signatures. Anyone visiting the site could potentially exploit these weaknesses to weaken the overall security of the login process to read private information and change some data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate SAML SSO - Service Provider to 3.2.0.

For developers: what the fix changed

This release carries 11 security fixes. The summary below is for SA-CONTRIB-2026-144, the most serious of them.

It is unclear where the predictable random number generation is fixed as the diff is truncated, but the signature comparison logic is updated in the verify function of src/Utilities.php to use strict type checking. The update also introduces unmentioned security improvements including XML external entity and server side request forgery protections.

The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.

Also in this release The release removes unused configuration and routes, adds local relay state validation, and implements replay attack protection for SAML assertions.

3.1.4 to 3.2.0 1 commit, 16 files.

  • config/install/miniorange_saml.settings.yml +0 −1
  • config/schema/miniorange_saml.schema.yml +19 −10
  • miniorange_saml.install +8 −0
  • miniorange_saml.routing.yml +1 −9
  • src/Api/MoAuthApi.php +0 −46
  • src/Controller/MiniorangeSamlController.php +5 −44
  • src/Form/MiniorangeSpInfo.php +97 −6
  • src/Form/MiniorangeTrial.php +0 −51
  • src/MiniOrangeSamlAcs.php +175 −46
  • src/MiniorangeSamlConstant.php +0 −3
  • src/MiniorangeSamlSpRegistration.php +0 −414
  • src/MiniorangeSamlSupport.php +1 −1

Full diff, 3.1.4 to 3.2.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 11 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Taxonomy Term Glossary

Critical · 258 sites report using it · SA-CONTRIB-2026-152 · on drupal.org

This module automatically highlights specific words or categories when they appear in the text of a website.

The module does not properly check access rights for categories. Anyone visiting the site could see a list of all categories through a data feed including hidden or unpublished ones. They could not change or delete any of this information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Taxonomy Term Glossary to 4.6.0.

For developers: what the fix changed

The fix updates loadGlossaryTerm in src/Controller/TermGlossaryController.php to ensure the requested term belongs to a configured vocabulary. It also modifies buildCachedJsonResponse to only set public cache headers for anonymous users, preventing restricted terms viewed by authenticated users from being cached and served to others.

Also in this release The release also fixes a bug where a hook received the wrong argument, refactors term storage, and adds tests.

4.5.2 to 4.6.0 4 commits, 11 files including 7 tests.

  • .cspell-project-words.txt +1 −0
  • README.md +4 −2
  • src/Controller/TermGlossaryController.php +40 −13 fix
  • src/Service/TermGlossaryManager.php +3 −11

Full diff, 4.5.2 to 4.6.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Ultimate Table Field

Critical · 163 sites report using it · SA-CONTRIB-2026-153 · on drupal.org

This module allows a website to store and display information in rows and columns and lets editors update individual cells.

The page used to edit table cells is not properly protected. Anyone visiting the site could open this page and upload document files to the server. They could change or add some data but they could not read any private information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Ultimate Table Field to 2.0.1 or 1.1.1, whichever branch you are on.

For developers: what the fix changed

The fix introduces a new permission in ultimate_table_field.permissions.yml and applies it to the ultimate_table_field.open_modal_form route in ultimate_table_field.routing.yml. It also adds an access check to the modalLinkBuilder function in src/Element/UltimateTableTrait.php to hide the link for users without the permission.

Also in this release A post update hook was added to inform administrators about the new permission, and the README was updated.

2.0.0 to 2.0.1 1 commit, 5 files.

  • README.md +10 −0
  • src/Element/UltimateTableTrait.php +13 −5 fix
  • ultimate_table_field.permissions.yml +3 −0 fix
  • ultimate_table_field.post_update.php +13 −0
  • ultimate_table_field.routing.yml +1 −1 fix

Full diff, 2.0.0 to 2.0.1 · Full diff, 1.1.0 to 1.1.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Patreon

Critical · 18 sites report using it · SA-CONTRIB-2026-139 · on drupal.org

This module connects a website to a creator funding platform.

This project has been withdrawn because of a security problem its maintainer did not fix. The details are not published and it should be treated as unsafe to keep. An administrator could read any private information and change any data including the code itself.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Patreon. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Moderately critical: 4 updates

Include in your next routine update, within the month.

Key auth

Moderately critical · 5,630 sites report using it · SA-CONTRIB-2026-138 · on drupal.org

This module allows users to log in using a special security key instead of a username and password.

The module does not store pages separately for each user when caching is turned on. A user with an ordinary account could see the security keys belonging to another user with the same access rights to read private information and change some data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if the dynamic page cache module is turned on.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Key auth to 2.2.4.

For developers: what the fix changed

The fix updates src/Form/UserKeyAuthForm.php to explicitly add per user caching to the access results in buildForm and checkAccess.

Also in this release Added a test for view only key access.

2.2.3 to 2.2.4 3 commits, 2 files including 1 test.

  • src/Form/UserKeyAuthForm.php +20 −13 fix

Full diff, 2.2.3 to 2.2.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Feed Block

Moderately critical · 530 sites report using it · SA-CONTRIB-2026-137 · on drupal.org

This module displays lists of articles from external data feeds in small boxes on the website.

The module does not properly clean up the external data feed before displaying it on the screen. A user with an ordinary account could insert harmful scripts into the feed that run when someone views the page to read private information and change some data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Feed Block to 3.0.2 or 2.0.2, whichever branch you are on.

For developers: what the fix changed

The fix sanitises feed item URLs using `UrlHelper::stripDangerousProtocols()` and validates them with `UrlHelper::isValid()` in `RSSFeedFormatter.php`. It also changes the feed URL input field type from textfield to url in `RSSFeedWidget.php`.

Also in this release The release adds a security warning to the module help text and introduces a test module to mock feed requests.

3.0.1 to 3.0.2 3 commits, 7 files including 4 tests.

  • src/Hook/FeedBlockHooks.php +2 −0
  • src/Plugin/Field/FieldFormatter/RSSFeedFormatter.php +21 −11 fix
  • src/Plugin/Field/FieldWidget/RSSFeedWidget.php +1 −1 fix

Full diff, 3.0.1 to 3.0.2 · Full diff, 2.0.1 to 2.0.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Central Authentication System (CAS) Server

Moderately critical · 303 sites report using it · SA-CONTRIB-2026-135 · on drupal.org

This module turns the website into a central login hub that allows users to access other connected systems.

The module does not properly check the web address used to send users to a new page after they log out. Anyone visiting the site could trick a user into clicking a link that sends them to a malicious external website. They could not read any private information or change any data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if an attacker can convince a user to click a specially crafted link.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Central Authentication System (CAS) Server to 2.0.4 or 2.1.3, whichever branch you are on.

For developers: what the fix changed

The fix validates the service URL during logout in the UserActionController class by checking it against the configuration helper. If the service is invalid it returns an error message.

2.0.3 to 2.0.4 1 commit, 1 file.

  • src/Controller/UserActionController.php +6 −0 fix

Full diff, 2.0.3 to 2.0.4 · Full diff, 2.1.2 to 2.1.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

SafeDelete

Moderately critical · 5 sites report using it · SA-CONTRIB-2026-140 · on drupal.org

This module helps manage the removal of content and provides reports to find pieces of content that are no longer linked to anything.

The module does not properly clean up the titles of content when displaying the report. A user with an ordinary account could insert harmful scripts into a title which would run when someone views the report to read private information and change some data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if an attacker has the access right to create a piece of content that appears in the report.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate SafeDelete to 1.0.88.

For developers: what the fix changed

The fix removes the raw filter from the node title in the templates/safedelete-orphanedpages.html.twig template and sanitises the title using PlainTextOutput::renderFromHtml in safedelete.module.

1.0.87 to 1.0.88 2 commits, 2 files.

  • safedelete.module +3 −2 fix
  • templates/safedelete-orphanedpages.html.twig +1 −1 fix

Full diff, 1.0.87 to 1.0.88

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.