Drupal Security Team Warns of Critical Contributed Module Security Release on 23 September
Site operators have advance notice of a critical contributed module security release scheduled for 23 September 2026, but not yet the name of the affected project. In PSA-2026-09-21, the Drupal Security Team says releases for a widely used contributed module will be published between 17:00 and 21:00 UTC. The highest-rated advisory currently carries a Critical score of 16/25, while Drupal core is not affected.
The Security Team updated the PSA on 22 September to warn that advisories included in the release may be exploitable under more common configurations than the highest-rated advisory's current risk vector suggests. It also says other contributed projects may publish advisories on the same date, potentially involving more severe vulnerabilities. An earlier update confirmed that the announced releases will not be covered by Drupal Steward. The affected module, affected and fixed versions, CVE identifiers, and project-specific mitigations have not yet been disclosed.
The highest-rated advisory currently has the vector AC:Basic/A:User/CI:All/II:All/E:Theoretical/TD:Uncommon. Under Drupal's security risk definitions, A:User means exploitation requires user-level access with basic or commonly assigned permissions, E:Theoretical means no public exploit code or documentation for developing an exploit is known, and TD:Uncommon means only uncommon configurations are exploitable. Those values apply to that currently highest-scored advisory; the PSA separately warns that other advisories may involve anonymous access, default configurations, or more common configurations.
Publication may be staggered across the four-hour window, with advisories released individually or in batches grouped by module. The Security Team plans to announce in Slack when all scheduled releases are complete and to send mailing-list messages together at the end of the window. The PSA says the planned update does not require special release procedures.
Before disclosure, site teams can review their contributed dependencies and confirm that backups, testing environments, and deployment procedures are ready. Drupal's module-update documentation recommends taking a database backup before updates, while its deployment guidance recommends testing changes away from production before deployment. Once the affected project is identified, operators can compare installed versions with the published affected and fixed ranges and review the advisory before updating. The PSA does not instruct site owners to update unrelated contributed projects in advance.
