Fresh #Drupal security patches:
• Examples for Developers (examples) → 4.0.6
• Tagify (tagify) → 1.2.52
If you use these modules on Drupal 10/11, now's a good time to update.
Security fixes out for #Drupal modules:
• Anti-Spam by CleanTalk (cleantalk) → 9.7.1
• Commerce Core (core) → 3.3.6
• TacJS (tacjs) → 6.8.0
• LocalGov Workflows (localgov_workflows) → 1.6.0
Update if you're using any of these on Drupal 10/11/9.
New #Drupal security fix:
Drupal AlternativeCommerce (Basket) (basket).
Update to 2.1.17 if you're on Drupal 10/11.
No action needed if you don't use this module.
Heads up #Drupal - new security updates:
• Date iCal → 4.0.15
• Colorbox Inline → 2.1.1
• Translate Drupal with GTranslate → 3.0.5
• Node View Permissions → 1.7.0/2.0.1
Worth updating if these are on your Drupal 10/11 site.
Security update just dropped for #Drupal module Automated Logout (autologout).
Update to 1.7.0/2.0.2 if you're on Drupal 10/11.
No action needed if you don't use this module.
#Drupal module updates for security:
• Unpublished Node Permissions (unpublished_node_permissions) → 1.7.0
• AI (Artificial Intelligence) (ai) → 1.2.12
Update if you're using any of these on Drupal 10/11.
Heads up #Drupal - new security updates:
• Islandora → 2.17.5
• CAPTCHA → 1.17.0
• Anti-Spam by CleanTalk → 9.7.0
• Tagify → 1.2.49
• Theme Negotiation by Rules → 1.2.1
• Material Icons → 2.0.4
If you use these modules on Drupal 10/11/9, now's a good time to update.
Heads up #Drupal - new security updates:
• UI Icons (ui_icons) → 1.0.1
• Quick Edit (quickedit) → 2.0.1
If you use these modules on Drupal 10/11, now's a good time to update.
#Drupal security update:
Login Disable module updated to 2.1.3 addressing access bypass vulnerability (SA-CONTRIB-2026-008).
Update if you have this module installed on Drupal 10 or 11. #DrupalSecurity
Heads up #Drupal - new security updates:
• Central Authentication System (CAS) Server (cas_server) → 2.1.2
• Drupal Canvas (canvas) → 1.0.4
If you use these modules on Drupal 10/11, now's a good time to update.
#Drupal security updates were just released.
Affected modules:
• Microsoft Entra ID SSO Login (<2.0.0)
• AT Internet Piano Analytics (<2.3.1, <1.0.1)
• AT Internet SmartTag (<1.0.1)
• Group Invite (<2.3.9, <3.0.4, <4.0.4)
Update if installed.
#Drupal 10/11/9 security update for HTTP Client Manager.
Update to 9.3.13 or 10.0.2 or 11.0.1 if you're on an older version.
Only matters if you have this module installed.
#Drupal core security updates released today.
Affecting Drupal 10.4–11.2
• SA-CORE-2025-008 – Information disclosure
• SA-CORE-2025-005 – Denial of Service
• SA-CORE-2025-006 – Gadget chain
All sites on supported branches must update to:
10.4.9 / 10.5.6 / 11.1.9 / 11.2.8
#Drupal security updates released today.
Modules affected:
• Simple multi step form (<2.0.0) — Cross-site Scripting (CVE-2025-12761)
• Email TFA (<2.0.6) — Access bypass (CVE-2025-12760)
Update only if these modules are installed.