Security starts with a supported version

Drupal Security

Most Drupal security problems trace back to one thing: running a version that no longer gets patched. Here's how Drupal security releases work, why end-of-life versions are a growing risk, and how to stay protected.

How Drupal security works

Drupal has a dedicated Security Team that reviews reports and publishes security advisories and patches for supported versions of Drupal core and contributed modules. As long as you're on a supported version and apply updates, you're covered by that process.

The moment a version reaches end of life, that coverage stops. No more advisories, no more patches — and any vulnerability discovered afterward is never officially fixed for that version.

End of life is the single biggest Drupal security risk. Attackers actively scan the web for known, unpatched Drupal installations. An unsupported site isn't just "a bit behind" — it's exposed to vulnerabilities that already have public fixes everywhere except your version.

Which versions are a risk right now

VersionStatusSecurity updates?
Drupal 7End of lifeNo — since Jan 5, 2025
Drupal 8End of lifeNo — since Nov 2, 2021
Drupal 9End of lifeNo — since Nov 1, 2023
Drupal 10SupportedYes
Drupal 11CurrentYes

If you're on Drupal 7, 8, or 9, the durable security fix isn't a patch — it's getting onto a supported version. See the upgrade paths to Drupal 12.

Staying protected beyond the version

We're building out detailed write-ups of specific Drupal vulnerabilities and advisories here. In the meantime, if you're worried about a specific site, tell us about it below.

Worried a site is exposed?

Tell us what you're running as well as any additional tech stack details. From there we can figure out together if an upgrade makes the most sense — or if there's another option best suited for you and your organization.

Tell us what you need →

Tell us what you need

Share your site and any additional tech stack details. We'll detect your Drupal version, flag any end-of-life security risk, and figure out together the right way to get protected. No obligation.

We'll email you back and may follow up if we spot significant issues worth fixing. No spam.