How Drupal security works
Drupal has a dedicated Security Team that reviews reports and publishes security advisories and patches for supported versions of Drupal core and contributed modules. As long as you're on a supported version and apply updates, you're covered by that process.
The moment a version reaches end of life, that coverage stops. No more advisories, no more patches — and any vulnerability discovered afterward is never officially fixed for that version.
Which versions are a risk right now
| Version | Status | Security updates? |
|---|---|---|
| Drupal 7 | End of life | No — since Jan 5, 2025 |
| Drupal 8 | End of life | No — since Nov 2, 2021 |
| Drupal 9 | End of life | No — since Nov 1, 2023 |
| Drupal 10 | Supported | Yes |
| Drupal 11 | Current | Yes |
If you're on Drupal 7, 8, or 9, the durable security fix isn't a patch — it's getting onto a supported version. See the upgrade paths to Drupal 12.
Staying protected beyond the version
- Run a supported version and apply core + module security updates promptly.
- Keep PHP current — old Drupal forces old, unsupported PHP, compounding the exposure.
- Watch contributed modules — many advisories are for modules, not core.
- Modernize hosting — outdated infrastructure is often as risky as the CMS.
We're building out detailed write-ups of specific Drupal vulnerabilities and advisories here. In the meantime, if you're worried about a specific site, tell us about it below.
Worried a site is exposed?
Tell us what you're running as well as any additional tech stack details. From there we can figure out together if an upgrade makes the most sense — or if there's another option best suited for you and your organization.
Tell us what you need
Share your site and any additional tech stack details. We'll detect your Drupal version, flag any end-of-life security risk, and figure out together the right way to get protected. No obligation.
We'll email you back and may follow up if we spot significant issues worth fixing. No spam.