Drupal Security Team Marks 16 Contributed Projects Unsupported in Ten Weeks
Since 10 June 2026, the Drupal Security Team has marked 16 contributed projects unsupported for security reasons across five advisory dates. The latest three were added on 19 August: Gammu SMS Daemon, Link content parser, and Screenshot. Each advisory lists all versions as affected and tells sites using the project to uninstall it.
Unsupported-project advisories follow a different operational path from conventional Drupal security releases. Sites are not directed to patched versions because no supported release containing a fix is available. Drupal's procedure says a project may reach this point when maintainers do not respond after multiple attempts to resolve a reported security issue.
Drupal's contributed-project advisory archive shows three projects marked unsupported on 10 June, three on 8 July, five on 22 July, two on 29 July, and three on 19 August. The June batch covered Mother May I, Composer, and Brute force attack protection. The Composer advisory concerns the Drupal project named Composer, not the Composer PHP dependency manager. Together, the five advisory dates account for 16 projects over exactly ten weeks.
Every unsupported-project advisory in this sequence carries the same Critical 16/25 rating and the vector AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:All. The Drupal Security Team procedure instructs coordinators to use that rating regardless of the nature of the originally reported issue. Drupal says incomplete investigation can leave additional risks unknown, so it publishes a relatively high score as a reasonable estimate. The common rating therefore does not establish that all 16 projects contain equivalent vulnerabilities or share the same attack path.
The 19 August advisories assign six CVE identifiers across the latest three projects. SA-CONTRIB-2026-100 assigns CVE-2026-76755, CVE-2026-76756, and CVE-2026-76757 to Gammu SMS Daemon; SA-CONTRIB-2026-101 assigns CVE-2026-76758 to Link content parser; and SA-CONTRIB-2026-102 assigns CVE-2026-76759 and CVE-2026-76782 to Screenshot. The advisories do not disclose the technical flaws behind those CVEs.
As checked on 24 August 2026, Drupal.org project pages report one site using Gammu SMS Daemon, eight using Link content parser, and 24 using Screenshot. These are reporting-site figures, not counts of confirmed vulnerable or compromised installations. A single site can report using more than one affected project, so the figures should not be added as a count of distinct sites. They indicate limited reported reach for the latest batch without establishing how many distinct sites are exposed in practice.
The contrast is visible in the five contributed-project security advisories published on 12 August. Commerce PayPal, Diff, Entity Share Websub, External Authentication, and Quick Tabs had security releases available, as The DropTimes previously reported. Sites affected by those advisories had an update path, while projects in the unsupported sequence do not.
Drupal's public advisories establish the concentration of unsupported-project notices since June but do not explain why they have clustered during this period. A contributor with permission to opt projects into security advisory coverage can seek to take over an affected project and work privately with the Security Team on the unresolved issue. Drupal recommends resolving the issue within 30 calendar days after publication where realistic and says technical details may be made public if it remains unresolved. Until an advisory is updated, Drupal's published solution for sites using these projects remains uninstalling them.
References
-
Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 (19 August 2026)
-
Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101 (19 August 2026)
-
Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 (19 August 2026)
-
