07/15/2026
Drupal released a core security update today (SA-CORE-2026-010, 011 & 012).
Because this is Drupal core — not an add-on module — EVERY Drupal 10 and 11 site is affected.
The issue: cross-site scripting (XSS) and information-disclosure vulnerabilities that could let an attacker run malicious code in visitors' browsers or expose data.
What to do:
- Drupal 10 sites: update core to 10.6.13
- Drupal 11 sites: update core to 11.4.4
- Rated "Moderately Critical" by the Drupal Security Team
06/24/2026
Security update for Drupal sites.
Salesforce Suite (salesforce) needs to be updated to version 5.1.3.
The issue: Without the update, someone could potentially trick an admin into performing unwanted actions.
This applies to Drupal 10/11 sites.
Geolocation Field (geolocation) needs to be updated to version 3.15.0.
The issue: Without the update, someone could potentially access or modify your database without permission.
This applies to Drupal 10/11 sites.
Paragraphs (paragraphs) needs to be updated to version 1.21.0.
The issue: Without the update, someone could potentially access parts of your site they shouldn't be able to see.
This applies to Drupal 10/11 sites.
This only affects sites using this specific module. If you're not sure whether your site uses it, we can help you check.
06/17/2026
Security update for Drupal sites.
Drupal core (core) needs to be updated to version 10.5.12 and 10.6.11 and 11.2.14 and 11.3.12.
The issue: Without the update, someone could potentially compromise your site's security.
This applies to ALL Drupal 10/11 sites.
06/10/2026
Security update for Drupal sites.
Examples for Developers (examples) needs to be updated to version 4.0.6.
The issue: Without the update, someone could potentially access parts of your site they shouldn't be able to see.
This applies to Drupal 10/11 sites.
Tagify (tagify) needs to be updated to version 1.2.52.
The issue: Without the update, someone could potentially inject malicious code that runs in visitors' browsers.
This applies to Drupal 10/11 sites.
This only affects sites using this specific module. If you're not sure whether your site uses it, we can help you check.
06/03/2026
Drupal released a security update today.
Anti-Spam by CleanTalk (cleantalk) has a security issue that could let someone compromise your site's security.
If you have this module on your site:
- Versions below 9.7.1 are affected
- Update to version 9.7.1
- This applies to Drupal 9 sites
Commerce Core (core) has a security issue that could let someone compromise your site's security.
If you have this module on your site:
- Versions below 3.3.6 are affected
- Update to version 3.3.6
- This applies to Drupal 10/11 sites
TacJS (tacjs) has a security issue that could let someone compromise your site's security.
If you have this module on your site:
- Versions below 6.8.0 are affected
- Update to version 6.8.0
- This applies to Drupal 10/11 sites
If you don't have this module installed, no action needed.
04/15/2026
Drupal released a security update today.
Drupal core (core) has a CRITICAL security issue that could let someone inject malicious code that runs in visitors' browsers.
If you have this module on your site:
- Versions below 11.3.7 and 10.6.7 are affected
- Update to version 11.3.7 and 10.6.7
- This applies to Drupal 10/11 sites
If you don't have this module installed, no action needed.