logo

Drupal critical update to fix bug with high exploitation risk

ID: 45e819bd-2714-5d95-9a4f-42e337ba3edf

STIX ID: report--45e819bd-2714-5d95-9a4f-42e337ba3edf

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Bill Toulas

...
...

Drupal announced a critical core security release scheduled for May 20 (17:00–21:00 UTC) affecting Drupal core 8 and later and strongly urged administrators to update (recommended minimum: 10.6). Security updates will be provided for multiple 10.x/11.x releases, with hotfixes available for certain end-of-life 8.9 and 9.5 builds; no technical details have been published and Drupal warned that threat actors could develop exploits within hours, so sites should monitor the official security portal and apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.