Drupal PSA Security
Upcoming critical contributed project security release on September 23, 2026 - PSA-2026-09-21
- Updated 2026-09-22, 12:00 UTC, to document that the advisories in the release might be possible for more common configurations, and that other projects may have advisories.
- Updated 2026-09-21, 19:00 UTC, to document that this is not covered by Drupal Steward.
There will be a security release for a widely used contributed module on September 23, 2026 between 17:00 and 21:00 UTC.
We are announcing this release in advance because the affected contributed module is used on a significant portion of Drupal sites, and the upcoming release will include a significant number of advisories.
The advisory with the highest risk score for the release is currently rated as critical. Other, less severe advisories in the release may be accessible to anonymous users, or result from default configurations.
Other contributed projects may also release advisories on the same date, possibly with more severe vulnerabilities. Drupal core is not affected.
Drupal Steward informationThese releases will not be covered by Drupal Steward.
Advisories may be published in batches (a few at a time)The current rate of advisories may require changes to our practices going forward:
- The security team may publish advisories individually, at different times inside the window.
- We will try to publish batches grouped by module.
- We will announce in Slack when all planned releases for the day are complete.
- We will release mailing list emails about the security updates together at the end of the window, to reduce the risk of site owners updating multiple times while advisories are still being published.
These changes are intended to make the process easier for the team and to make communication from the team easier to follow.
No special release proceduresThe planned update does not require special release procedures.
Solution:Update, 2026-09-23 18:30 UTC: The Webform project has released the below 20 advisories today. Make note of the critical advisory SA-CONTRIB-2026-175, which has slightly increased severity than was originally noted in this public service announcement.
Other advisories than those below were published for other projects, so site owners should follow all normal update procedures.
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155
- (Advisory numbers 156 and 157 were accidentally skipped in how we applied the numbering; these are not missing security advisories.)
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
- Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
- Webform - Less critical - Access bypass - SA-CONTRIB-2026-165
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169
- Webform - Less critical - Denial of service - SA-CONTRIB-2026-170
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
- Webform - Less critical - Access bypass - SA-CONTRIB-2026-173
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
- Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Moshe Weitzman (moshe weitzman) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Security advisory coverage removed - QA Accounts - PSA-2026-07-22
QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.
Solution:Ensure qa_accounts is not enabled on any publicly available site.
Reported By: Fixed By:
Neue Kommentare
vor 1 Woche 6 Tagen
vor 2 Wochen 2 Tagen
vor 2 Wochen 4 Tagen
vor 3 Wochen 1 Stunde
vor 3 Wochen 13 Stunden
vor 3 Wochen 13 Stunden
vor 3 Wochen 13 Stunden
vor 3 Wochen 3 Tagen
vor 3 Wochen 4 Tagen
vor 3 Wochen 4 Tagen