Drupal

Drupal Association · current 11.4.5

The current version of Drupal is 11.4.5 (as of 06/08/2026). patchletter checks the official source daily and emails you every new release.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.

  • CVE-2018-7600Drupal Core Remote Code Execution VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2020-13671Drupal core Un-restricted Upload of File

    8.8 high · over the network, with a basic account · CISA deadline was 18 Jul 22

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Drupal at a glance

Drupal is a powerful open-source CMS used for complex and enterprise websites. Drupal ships regular core releases plus coordinated security advisories on scheduled windows; as an internet-facing CMS, prompt patching is essential — the project's security team is well organized, and so are attackers.

For admins the coordinated security releases are the rhythm: Drupal announces core and contributed-module advisories on set days, and past critical flaws (the Drupalgeddon class) were exploited within hours — apply security updates immediately. Keep to a supported Drupal version and track its end-of-life, since running an unsupported major is a serious exposure. Contributed modules are the usual attack surface — keep them minimal, current and from the project. Updates run database updates — back up first and test on staging. Keep the underlying PHP supported. After updating, verify the site and modules. Patchletter surfaces new Drupal releases and security advisories.

Support cycles (endoflife.date)

CycleLatest versionStatus
11.411.4.5EOL 7 Jul 27
11.311.3.16EOL 16 Dec
10.610.6.15EOL 16 Dec
11.211.2.14End of Life
10.510.5.12End of Life
10.410.4.10End of Life
11.111.1.10End of Life
11.011.0.13End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
11.4.5STABLE06/08/2026
11.4.4STABLE15/07/2026
11.4.3STABLE14/07/2026
11.4.2STABLE10/07/2026
11.4.1STABLE03/07/2026
11.3.16STABLE23/07/2026
11.3.14STABLE15/07/2026
11.3.13STABLE23/06/2026
11.2.14STABLE17/06/2026
11.1.10STABLE20/05/2026
11.0.13STABLE19/03/2025
10.6.15STABLE06/08/2026
10.6.14STABLE23/07/2026
10.6.13STABLE15/07/2026
10.6.12STABLE23/06/2026
10.5.12STABLE17/06/2026
10.4.10STABLE20/05/2026
10.3.14STABLE19/03/2025
10.2.12STABLE22/11/2024
10.1.8STABLE16/01/2024
10.0.11STABLE19/09/2023
9.5.11STABLE19/09/2023
9.4.15STABLE03/05/2023
9.3.22STABLE28/09/2022
9.2.21STABLE10/06/2022
9.1.15STABLE24/11/2021
9.0.14STABLE25/05/2021
8.9.20STABLE17/11/2021
8.8.12STABLE25/11/2020
7.103LTS04/12/2024

Frequently asked questions

What is the latest version of Drupal?
Drupal 11.4.5, released 06/08/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Drupal release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Drupal updates?
Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.

Never miss a Drupal update

We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.

Watch Drupal

Embed this badge

Shows the current Drupal version and updates itself. Free to use, no account needed.

Drupal badge
[![Drupal](https://patchletter.com/badge/drupal.svg)](https://patchletter.com/en/software/drupal)
https://patchletter.com/badge/drupal.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Servers & Databases