Skip to main content

Drupal Releases Security Updates

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

Drupal 9.1 Versions: all prior to 9.1.9

Drupal 9.0 Versions: all prior to 9.0.14

Drupal 8.9 Versions: all prior to 8.9.16

Versions of Drupal 8 prior to 8.9.x are end-of-life and do not receive security coverage


Threat details

Introduction

Drupal has released security updates to address a vulnerability affecting Drupal. An attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Organisations are encouraged to review Drupal Advisory SA-CORE-2021-003 and apply the necessary updates or mitigations.

Last edited: 1 June 2021 12:19 pm