The Drupal Security Team’s 17 June 2026 advisory batch affects supported Drupal 10 and 11 branches and three contributed modules. The most consequential issues involve PHP object injection under rare JSON:API write conditions, server-side request forgery through oEmbed URL discovery, and incomplete validation of MIME types during image uploads. Site teams should treat the batch as an update and configuration check, not as a single universal Drupal exposure, because several critical advisories depend on specific field types, write permissions, or module installations.
...more