The Drupal Security Team published 26 contrib advisories across 25 projects, including a highly critical Block AJAX flaw and seven critical notices. Several fixes also require follow-up steps beyond updating packages.

The Drupal Security Team published 26 contrib advisories across 25 projects, including a highly critical Block AJAX flaw and seven critical notices. Several fixes also require follow-up steps beyond updating packages.
Two new guides tackle different operational risks around modern Drupal: DrupalFit focuses on site security, while Pantheon examines reliability and governance in decoupled CMS deployments.
Drupal core security updates fix a CKEditor 5 XSS vulnerability. A user who can create or edit content may target someone who later opens it through CKEditor, including privileged administrators.
Update to 10.6.17, 11.3.17, or 11.4.7.
Researcher Matan Kotick says Claude found and validated a Critical SQL injection in the amazee[.]ai Private AI Provider in about ten minutes. Drupal’s advisory confirms CVE-2026-87936 and the affected code path.
Larger Drupal security-advisory batches may reflect cheaper AI-assisted vulnerability discovery, not suddenly worse contrib code. The initiative reported 30+ issues and contributions to 10+ advisories and CVEs in six weeks.
Drupal’s September 2 security batch includes 16 advisories across 14 contrib projects. Five are Critical, covering issues including account takeover, access bypass, and XSS. Corrective releases are available.