CMS Drupal: Highly critical Drupal core update announced for May 20
A critical security update for Drupal Core will be released on the evening of Wednesday, May 20. Admins should install it quickly.
(Image: JLStock/Shutterstock.com)
The maintainers of the open-source content management system Drupal have announced that they will release a highly critical security update for Drupal Core on the evening of Wednesday, May 20, 2026. IT managers should install it promptly.
In the advance notice of the security patch, the Drupal security team writes that the update is scheduled to be released between 7 PM and 11 PM local time (5:00 PM - 9:00 PM UTC). The developers point out that admins should urgently make time to apply the Drupal Core update, as exploits could be developed within hours or days of the fix being released.
Fortunately, not all Drupal configurations will be equally affected. The programmers have not yet provided any information on the limitations, but admins should check at the time of release whether their instances are impacted and require an immediate update.
Updates only for supported versions
The updates are actually intended only for the still-supported Drupal Core versions 11.3.x, 11.2.x, 10.6.x, and 10.5.x. However, as an exception, patches for Drupal Core 11.1.x and 10.4.x are now also being provided, even though they are already at the end of their product support cycle. The developers cite the severity of the problem as the reason. The security team is even providing corrected software for Drupal Core 9.5 and 8.9.
Videos by heise
To apply the updates, installations with Drupal Core 11.1 and 11.0 should be updated to version 11.1.9. The development branches 10.4, 10.3, 10.2, 10.1, and 10.0, on the other hand, will first require version 10.4.9. For the even older versions, Drupal Core 9.5.11 and 8.9.20 are prerequisites. Those still using Drupal Core 7 are not affected by this particular issue.
The availability of the security update will then be announced this evening on Drupal's security page and on social media. Drupal Core admins should regularly check during this period whether the update is available and apply it immediately.
(dmk)