Drupal schedules urgent core security updates for today (May 20); site owners urged to reserve time
Drupal maintainers have warned they will publish a coordinated “core security release” covering all supported branches on May 20, 2026, during a four-hour window between 05:00 and 21:00 UTC. The Drupal Security Team is asking administrators to block out that time so they can verify whether their configurations are affected and apply fixes immediately, because weaponized exploits can appear within hours or days of a public advisory.
The exact vulnerability being fixed has not been disclosed yet, but the project treats the issue seriously-evidenced by the fact that the team is issuing additional patch releases for some end-of-life minor branches to help sites that cannot upgrade immediately. The maintainers have said mitigation steps will be included in the security advisory that accompanies the release.
To reduce last-minute problems, Drupal advises updating to the most recent patch release for your supported branch before the May 20 release window so you have time to resolve any upgrade complications ahead of the security announcement.
Maintainers expect patch releases to be available for the following supported core branches:
- 11.3.x
- 11.2.x
- 10.6.x
- 10.5.x
“Sites running a supported branch should apply the latest patch release for that branch now to prepare for the security window,” the project said in its advisory notice.
For sites still on older minor releases that are effectively end-of-life, Drupal is providing interim releases so those sites can apply the critical fix and then plan to upgrade to a fully supported branch. Specifically, sites on Drupal 11.1 or 11.0 are urged to move to at least Drupal 11.1.9, while sites on Drupal 10.4, 10.3, 10.2, 10.1, or 10.0 should update to at least Drupal 10.4.9. The recommended workflow is to install the security update as soon as it is published, and then perform a full upgrade to Drupal 11.3 or 10.6 in the near term.
For installations running end-of-life major versions-notably Drupal 8 and 9-Drupal will provide best-effort patch files for 8.9 and 9.5 that must be applied manually. The team cautions these backports are not guaranteed to be perfect and could introduce regressions or other issues; however, they may still reduce exposure until those sites can move to a supported release.
Drupal strongly recommends that sites on Drupal 8 or 9 plan to upgrade to at least Drupal 10.6 soon, noting that both Drupal 8 and 9 contain other previously disclosed vulnerabilities that will not be fixed by the emergency patches or by third-party extended-support offerings.
Additional targeted guidance from the project includes:
- Drupal 7: Not affected by this particular issue.
- Any Drupal 9 release: Update to 9.5.11.
- Any Drupal 8 release: Update to 8.9.20.
Site operators should prepare by scheduling maintenance time, ensuring backups and rollback plans are in place, and testing updates in staging environments as soon as Drupal publishes the advisory and patches.