Drupal has announced an emergency core security release scheduled for May 20, 2026, between 17:00 and 21:00 UTC. The vulnerability affects Drupal core versions 8 and later, though not all configurations are impacted. Security patches will be available for Drupal 10.4.x through 11.3.x. Even end-of-life versions 11.1.x and 10.4.x will receive fixes due to severity, and hotfix files will be published for EOL versions 9.5 and 8.9. Drupal warns that exploits could emerge within hours of the disclosure, urging administrators to apply updates immediately. No technical details have been released yet to prevent fraudulent exploitation of the advisory.
Table of contents
Related Articles:1 Impression