Drupal security updates, in plain English · Drupal core

Drupal core

Every Drupal site · on drupal.org · 5 security updates explained here

This is the main software that runs the website and lets people manage its content.

Below is every security update for Drupal core that this site has covered, newest first. Each one says who could exploit it, whether it applies to your site, how urgent it is, and what to tell your developer. Every Drupal site runs core, so each of these applies to yours unless it was already on a fixed version. If you are not sure which version your site is on, that is the first question to ask whoever looks after it.

Drupal core

Moderately critical · Drupal core · every Drupal site · SA-CORE-2026-013 · on drupal.org · Week of 16 September 2026

A person with an ordinary account who can create or edit content could hide harmful code on the site. If a site administrator or another user with access to the visual text editor views that content, the code could run and let the attacker view private information or change content. The attacker could not do this without someone else viewing the content first.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if the site is set up to use the CKEditor visual text editor.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal core to 11.4.7, 11.3.17 or 10.6.17, whichever branch you are on.

For developers: what the fix changed

The provided diff consists of minified CKEditor 5 build files, making it impossible to confidently isolate the specific changes that fix the XSS vulnerability in the engine package.

The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.

Also in this release The release updates the CKEditor 5 library to a new version, resulting in widespread minification and module ID changes across the compiled assets.

11.4.6 to 11.4.7 2 commits, 44 files including 1 test.

  • composer.lock +5 −5
  • composer/Metapackage/CoreRecommended/composer.json +2 −2
  • composer/Metapackage/DevDependencies/composer.json +1 −1
  • composer/Metapackage/PinnedDevDependencies/composer.json +2 −2
  • core/assets/vendor/ckeditor5/autosave/autosave.js +1 −1 fix
  • core/assets/vendor/ckeditor5/basic-styles/basic-styles.js +0 −0
  • core/assets/vendor/ckeditor5/block-quote/block-quote.js +1 −1 fix
  • core/assets/vendor/ckeditor5/bookmark/bookmark.js +0 −0
  • core/assets/vendor/ckeditor5/ckbox/ckbox.js +0 −0
  • core/assets/vendor/ckeditor5/ckeditor5-dll/ckeditor5-dll.js +0 −0
  • core/assets/vendor/ckeditor5/code-block/code-block.js +0 −0
  • core/assets/vendor/ckeditor5/editor-balloon/editor-balloon.js +1 −1 fix

Full diff, 11.4.6 to 11.4.7 · Full diff, 11.3.16 to 11.3.17 · Full diff, 10.6.16 to 10.6.17

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Drupal core

Moderately critical · Drupal core · every Drupal site · 3 security fixes · Week of 15 July 2026

3 security fixes in one update. Drupal core fixed 3 separate security bugs this week: 2 cross site scripting, 1 information disclosure. One update covers all of them. The most serious, SA-CORE-2026-012, is explained here and the full list is at the end of the card.

A person with an ordinary account could put hidden code into the name of a layout block. If another person uses the layout editing screen, that code would run. This could let the first person see private information or change content on the site.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies to sites where people use the layout editing screen.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal core to 11.4.4, 11.3.14 or 10.6.13, whichever branch you are on.

For developers: what the fix changed

This release carries 3 security fixes. The summary below is for SA-CORE-2026-012, the most serious of them.

The fix updates `core/modules/layout_builder/js/layout-builder.js` to use `textContent` instead of `innerHTML` when rendering the content preview placeholder label, preventing cross-site scripting.

Also in this release The release also includes fixes for two other vulnerabilities affecting the XSS utility and image style downloads, alongside version bumps.

11.4.3 to 11.4.4 4 commits, 8 files.

  • composer.lock +5 −5
  • composer/Metapackage/CoreRecommended/composer.json +2 −2
  • composer/Metapackage/DevDependencies/composer.json +1 −1
  • composer/Metapackage/PinnedDevDependencies/composer.json +2 −2
  • core/lib/Drupal.php +1 −1
  • core/lib/Drupal/Component/Utility/Xss.php +2 −0
  • core/modules/image/src/Controller/ImageStyleDownloadController.php +9 −9
  • core/modules/layout_builder/js/layout-builder.js +2 −2 fix

Full diff, 11.4.3 to 11.4.4 · Full diff, 11.3.13 to 11.3.14 · Full diff, 10.6.12 to 10.6.13

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 3 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Drupal core

Critical · Drupal core · every Drupal site · 5 security fixes · Week of 17 June 2026

5 security fixes in one update. Drupal core fixed 5 separate security bugs this week: 1 php object injection, 1 improper validation, 1 server side request forgery, 1 gadget chain, 1 cache poisoning and open redirect. One update covers all of them. The most serious, SA-CORE-2026-005, is explained here and the full list is at the end of the card.

An ordinary account on the site could inject malicious code through a data feed. This could allow them to view or alter any information on the site including the underlying code.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if it uses a specific type of reference field and allows write access through a data feed.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Drupal core to 11.3.12, 10.6.11, 11.2.14, 10.5.12 or 11.4.0-rc2, whichever branch you are on.

For developers: what the fix changed

This release carries 5 security fixes. The summary below is for SA-CORE-2026-005, the most serious of them.

The fix prevents PHP object injection by disabling class instantiation during unserialisation in PrimitiveDataNormalizer::doNormalize and by rejecting serialised string values for relationship meta fields in EntityResource::addToRelationshipData and EntityResource::doPatchMultipleRelationship.

Also in this release The release also includes fixes for several other security advisories, updating Guzzle dependencies, adding trusted host checks for oEmbed discovery and rebuild scripts, and improving file upload validation for images.

11.3.11 to 11.3.12 7 commits, 15 files including 1 test.

  • composer.lock +16 −15
  • composer/Metapackage/CoreRecommended/composer.json +2 −2
  • composer/Metapackage/PinnedDevDependencies/composer.json +1 −1
  • core/assets/scaffold/files/default.settings.php +17 −0
  • core/composer.json +1 −1
  • core/lib/Drupal.php +1 −1
  • core/lib/Drupal/Component/Datetime/DateTimePlus.php +1 −3
  • core/modules/file/src/Plugin/rest/resource/FileUploadResource.php +5 −0
  • core/modules/jsonapi/src/Controller/EntityResource.php +29 −3 fix
  • core/modules/jsonapi/src/Controller/FileUpload.php +4 −0
  • core/modules/media/src/OEmbed/UrlResolver.php +17 −0
  • core/modules/serialization/src/Normalizer/PrimitiveDataNormalizer.php +1 −1 fix

Full diff, 11.3.11 to 11.3.12 · Full diff, 10.6.10 to 10.6.11 · Full diff, 11.2.13 to 11.2.14 · Full diff, 10.5.11 to 10.5.12 · Full diff, 11.3.18 to 11.4.0-rc2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 5 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Drupal core

Highly critical · Drupal core · every Drupal site · SA-CORE-2026-004 · on drupal.org · Week of 20 May 2026

A flaw allows anyone on the internet to view any private information stored in the website database. They could also alter any content or add their own computer code to take over the system.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected by the main flaw if it uses a PostgreSQL database, and it might be affected by other underlying software flaws depending on its setup and extra features.
  • Has it been used in attacksYes. It has been used in real attacks.
  • How urgentDrupal rates this highly critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Drupal core to 10.6.9, 11.3.10, 10.5.10, 10.4.10 or 11.2.12, whichever branch you are on.

For developers: what the fix changed

The fix prevents SQL injection by ensuring that array values in SQL conditions are re-indexed using `array_values()` in `Condition::compile`, `ConditionAggregate::compile`, and the PostgreSQL-specific `Condition::translateCondition`, which stops malicious associative array keys from being injected into the query.

Also in this release The release also updated Symfony, Twig, and Underscore.js dependencies, and bumped the Drupal core version to 10.6.9.

10.6.8 to 10.6.9 4 commits, 19 files.

  • composer.json +1 −1
  • composer.lock +0 −0
  • composer/Metapackage/CoreRecommended/composer.json +32 −32
  • composer/Metapackage/DevDependencies/composer.json +1 −1
  • composer/Metapackage/PinnedDevDependencies/composer.json +9 −9
  • core/assets/vendor/underscore/underscore-min.js +0 −0
  • core/assets/vendor/underscore/underscore-min.js.map +0 −0
  • core/composer.json +6 −6
  • core/core.libraries.yml +2 −2
  • core/lib/Drupal.php +1 −1
  • core/lib/Drupal/Component/DependencyInjection/composer.json +1 −1
  • core/lib/Drupal/Component/EventDispatcher/composer.json +1 −1

Full diff, 10.6.8 to 10.6.9 · Full diff, 11.3.9 to 11.3.10 · Full diff, 10.5.9 to 10.5.10 · Full diff, 10.4.9 to 10.4.10 · Full diff, 11.2.11 to 11.2.12

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Drupal core

Critical · Drupal core · every Drupal site · 3 security fixes · Week of 15 April 2026

3 security fixes in one update. Drupal core fixed 3 separate security bugs this week: 2 cross site scripting, 1 gadget chain. One update covers all of them. The most serious, SA-CORE-2026-001, is explained here and the full list is at the end of the card.

A visitor without an account could cause unsafe code to run in message boxes on the site. This could allow them to see or change some information but they could not take over the whole site.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youEvery Drupal site on an affected version.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Drupal core to 11.3.7, 11.2.11, 10.6.7 or 10.5.9, whichever branch you are on.

For developers: what the fix changed

This release carries 3 security fixes. The summary below is for SA-CORE-2026-001, the most serious of them.

The fix sanitises button attributes for AJAX modal dialog boxes by applying Xss::filter to string values in the render method of core/lib/Drupal/Core/Ajax/OpenDialogCommand.php.

Also in this release The release also fixes two other security advisories and updates Composer to version 2.9.7.

11.3.6 to 11.3.7 5 commits, 8 files.

  • composer.lock +11 −11
  • composer/Metapackage/CoreRecommended/composer.json +1 −1
  • composer/Metapackage/PinnedDevDependencies/composer.json +2 −2
  • core/lib/Drupal.php +1 −1
  • core/lib/Drupal/Core/Ajax/OpenDialogCommand.php +15 −0 fix
  • core/lib/Drupal/Core/Template/Attribute.php +3 −0
  • core/modules/ckeditor5/src/Controller/EntityLinkSuggestionsController.php +1 −1
  • core/modules/views/src/ViewExecutable.php +27 −0

Full diff, 11.3.6 to 11.3.7 · Full diff, 11.2.10 to 11.2.11 · Full diff, 10.6.6 to 10.6.7 · Full diff, 10.5.8 to 10.5.9

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 3 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.