#DrupalSecurity
Researcher Matan Kotick says Claude found and validated a Critical SQL injection in the amazee[.]ai Private AI Provider in about ten minutes. Drupal’s advisory confirms CVE-2026-87936 and the affected code path.

https://bit.ly/4haV1cf
##Drupal #DrupalSecurity #Claude #DrupalAI
September 17, 2026 at 6:36 PM
🚨 Drupal.org has patched 4 core vulnerabilities, including cache poisoning and a gadget chain risk.
TDT breaks down SA-CORE-2025-005 to -008 + recommended updates.
Patch now: https://bit.ly/4hXWF0R
##Drupal #DrupalSecurity #SAcore #OpenSource
November 13, 2025 at 7:19 AM
📸🛠️ Bram Driesen doesn’t chase credit—he just keeps Drupal moving.
From event photos to security team work, his decade-long contribution is rooted in structure, respect, and community care.
Great profile by Alka Elizabeth:
🔗 https://bit.ly/4lOdXic ##Drupal #OpenSource #Community #DrupalSecurity
July 31, 2025 at 1:55 PM
It's time to patch your #Drupal !

Out Magical Support is already on it 💪

#Drupal #DrupalSecurity #SAcore #OpenSource
🚨 Drupal.org has patched 4 core vulnerabilities, including cache poisoning and a gadget chain risk.
TDT breaks down SA-CORE-2025-005 to -008 + recommended updates.
Patch now: https://bit.ly/4hXWF0R
##Drupal #DrupalSecurity #SAcore #OpenSource
November 13, 2025 at 9:15 AM
CleanTalk released Anti-Spam module 9.7.0 for Drupal, fixing a cross-site scripting issue reported in SA-CONTRIB-2026-014. The update also improves Spam FireWall handling, stability, and PHP 8.4 compatibility.

https://bit.ly/4lhABju
##Drupal #DrupalSecurity #DrupalDev #OpenSource
March 10, 2026 at 6:09 PM
Drupal core 11.4.4, 11.3.14, and 10.6.13 fix two XSS issues and one information disclosure issue. Drupal 10’s HTMX change hardens affected contrib modules.

https://bit.ly/4hg6DMP
##Drupal #DrupalCore #DrupalSecurity
July 17, 2026 at 12:52 PM
Larger Drupal security-advisory batches may reflect cheaper AI-assisted vulnerability discovery, not suddenly worse contrib code. The initiative reported 30+ issues and contributions to 10+ advisories and CVEs in six weeks.

https://bit.ly/4yM9JOo
##Drupal #DrupalSecurity #DrupalAI #OpenSource
Digital Matters Links Larger Drupal Advisory Batches to AI-Assisted Discovery
Large advisory batches can resemble a sudden decline in contributed-project security. Digital Matters argues that Drupal’s recent numbers should instead be read alongside changes in how vulnerabilities are being discovered.
bit.ly
September 17, 2026 at 12:49 PM
Update your Drupal sites as soon as possible, a critical issue was disclosed yesterday, Wednesday 19th:

https://www.drupal.org/sa-core-2025-001

Stay safe!

#Drupal #DrupalSecurity

www.drupal.org
February 20, 2025 at 7:59 AM
Sixteen Drupal contributed projects were marked unsupported for security reasons across ten weeks.

There is no supported patched release; Drupal advises affected sites to uninstall them.

https://bit.ly/3UbH2LK
##Drupal #DrupalSecurity #OpenSource
August 24, 2026 at 6:26 PM
Drupal’s 2026 core security advisories offer a clear AI governance lesson.

SA-CORE-2026-004 was not AI-caused, but production code still needs review, ownership, and patch readiness.

https://bit.ly/4wmDR1w
##Drupal #DrupalSecurity #AI #OpenSource
July 7, 2026 at 2:43 PM
Drupal Security Team published eight advisories on 17 June: five for core, three for contrib.

Core fixes cover JSON:API, oEmbed, image upload validation, and deserialization risks.

https://bit.ly/4oBXorV
##Drupal #DrupalSecurity #JSONAPI #DrupalCore
June 18, 2026 at 2:45 PM
Follow @drupalsecurity and be ready to upgrade your #drupal tomorrow, depending on the nature of the vulnerability it might be quickly and easily exploitable:

https://www.drupal.org/psa-2026-05-18

Our clients will be patched on stage as soon as the update drops, please watch out for tickets […]
Original post on toots.codeenigma.com
toots.codeenigma.com
May 19, 2026 at 3:36 PM
Five Drupal contrib security advisories are moderately critical: four access bypasses and one SSRF. Affected sites should check Commerce PayPal, Diff, Entity Share Websub, External Authentication and Quick Tabs.
##Drupal #DrupalSecurity #OpenSource

https://bit.ly/4gb9cOk
August 13, 2026 at 2:17 PM
Drupal’s latest contrib advisories require two different responses: update supported modules and remove unsupported projects.

Fixes address access bypass and XSS, while five projects have no patched release.

https://bit.ly/45l4UyC
##Drupal #DrupalSecurity #ContribModules #WebSecurity
July 23, 2026 at 6:35 PM
Greg Knaddison announced that Drupal security issues have moved from the legacy tracker to GitLab.

The workflow adds automated testing for core and contrib security fixes, advisory automation, and threaded reviews.

https://bit.ly/4wuIxD5
##Drupal #DrupalSecurity #GitLab #OpenSource
July 28, 2026 at 4:51 PM
Drupal core security updates fix a CKEditor 5 XSS vulnerability. A user who can create or edit content may target someone who later opens it through CKEditor, including privileged administrators.

Update to 10.6.17, 11.3.17, or 11.4.7.

https://bit.ly/4hxDe0j
##DrupalSecurity #CKEditor #WebSecurity
Drupal Core Security Update Fixes CKEditor XSS in Content Editing Workflow
Sites on Drupal 10.5.x and Drupal 11.2.x or earlier are outside security coverage, making a move to a supported branch part of the response.
bit.ly
September 17, 2026 at 7:16 PM
🔐 New module alert: Secret Login for #Drupal

Created by Vishal Kumar Yadav, it offers secure URL and token-based login — no username or password needed. Great for dev, staging, and test workflows.

🔗 Details via TDT: https://bit.ly/45PdYNO
##WebDev #CMS #DrupalSecurity #DevTools
Secret Login Module Introduces Secure URL and Token-Based Access for Drupal
Vishal Kumar Yadav’s Secret Login module enables Drupal administrators and developers to bypass the standard login form using configurable backdoor URLs or one-hour one-time tokens, streamlining access across development, staging and production envir...
bit.ly
July 4, 2025 at 1:39 PM
Drupal’s September 2 security batch includes 16 advisories across 14 contrib projects. Five are Critical, covering issues including account takeover, access bypass, and XSS. Corrective releases are available.

https://bit.ly/46awHCs
##Drupal #DrupalSecurity #SecurityAdvisory
September 7, 2026 at 7:14 PM
Two Drupal contrib security advisories require updates: Entity Browser fixes stored XSS in 8.x-2.16, while Edit in-place field 2.1.1 fixes an access-bypass vulnerability.

https://bit.ly/4q03Bia
##Drupal #DrupalSecurity #CyberSecurity
August 7, 2026 at 1:44 PM
UI Patterns 2.0.0–2.0.16 are affected by CVE-2026-15084, a moderately critical XSS flaw involving component markup. Update to a current fixed 2.x release.

https://bit.ly/4xriU62
##Drupal #DrupalSecurity #UIPatterns
Drupal UI Patterns XSS Fix: CVE-2026-15084
A July security update fixed insufficient sanitisation of markup passed to UI Patterns components. Follow-up work moved escaping closer to render time, while UI Patterns 2.0.19 is now the current stable release.
bit.ly
August 7, 2026 at 1:36 PM
Drupal 7 extended support may supply covered patches without transferring responsibility for custom code, integrations, hosting, testing, or migration. The Drop Times maps the ownership gaps teams must assign.

https://bit.ly/4bovwCl
##Drupal7 #DrupalSecurity #DrupalMigration
July 30, 2026 at 4:24 PM
Public upload misconfiguration can turn trusted Drupal domains into search-spam hosts.

This is not a new Webform vulnerability. Untrusted uploads should use private storage, restricted permissions, and verified cleanup.

https://bit.ly/4bXDTVA
##Drupal #DrupalSecurity #WebSecurity #Webform
July 23, 2026 at 6:09 PM
DrupalFit’s M&S cyber incident case study highlights a Drupal-relevant lesson: help desk verification, MFA processes, Active Directory access, and vendor controls all affect operational security.

https://bit.ly/4veN3E8
##Drupal #Cybersecurity #DrupalSecurity #InfoSec
DrupalFit Case Study Examines Marks & Spencer Cyber Incident
A retail ransomware incident becomes a warning for web teams when the weak point is not a module or server, but the process that grants access.
bit.ly
July 6, 2026 at 3:32 PM
Drupal.org advisories flag trust-boundary risks in contributed projects: Colorbox, FlowDrop, and Drupal Canvas.

A new summary covers XSS, access bypass, and upload-validation fixes Drupal teams should review.

https://bit.ly/4vta9ap
##Drupal #DrupalSecurity #WebSecurity
July 2, 2026 at 1:58 PM
Any thoughts @drupalsecurity??
Hey @drupalsecurity I am not always getting all the e-mails weds. If I do they are coming very late FYI. What’s the best channel these days
March 24, 2025 at 11:25 AM