Drupal Security Advisories
The Drupal Security Team publishes advisories for Drupal core (SA-CORE) and contributed modules (SA-CONTRIB). Drupal powers a long tail of government and enterprise sites, and past core vulnerabilities (“Drupalgeddon”) saw mass exploitation within hours of disclosure.
CSIRTS.com ingests Drupal Security Advisories every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes SA-CORE and SA-CONTRIB security advisories. Also available via RSS, JSON API and the MCP server.
Latest from Drupal Security Advisories
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002
Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001
Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004
Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003
Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002
Drupal core - Critical - Cross site scripting - SA-CORE-2025-001
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007
Drupal core - Less critical - Gadget chain - SA-CORE-2024-006
Never miss a Drupal Security Advisories advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.