Drupal security advisory (AV26-615)
Serial number: AV26-615 Date: June 18, 2026 On June 17, 2026, Drupal published security advisories to address vulnerabilities in a number of products. Included were critical updates for the following: Drupal core – multiple versions Plotly.js Graphing – versions prior to 3.0.2 Flag attendance field – versions prior to 8.x-1.2 Formatter Field – versions prior to 2.0.0 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations. Drupal Security Advisories
CSIRTS triage
- What
- Drupal published security advisories to address vulnerabilities in multiple products.
- Who is affected
- Users and administrators of affected Drupal products.
- Urgency
- Remediation is critical due to the severity of the vulnerabilities.
- Action
- Review the provided web link and apply the necessary updates or perform the suggested mitigations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Drupal core
Get an email when a new Drupal core advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/drupal-security-advisory-av26-615
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24