The current version of Drupal is 11.4.9 (as of 09/10/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
9.8 critical · over the network, without login · CISA deadline was 3 May 22
- CVE-2020-13671Drupal core Un-restricted Upload of File
8.8 high · over the network, with a basic account · CISA deadline was 18 Jul 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Drupal Erweiterungen: Mehrere Schwachstellen
WID-SEC-W-2026-3819 · 9 Oct
- Drupal Erweiterungen: Mehrere Schwachstellen
WID-SEC-W-2026-3554 · 24 Sept
- Drupal Core: Schwachstelle ermöglicht Cross-Site Scripting
WID-SEC-W-2026-3415 · 17 Sept
- Drupal Erweiterungen: Mehrere Schwachstellen
WID-SEC-W-2026-3284 · 10 Sept
- Drupal Module: Mehrere Schwachstellen
WID-SEC-W-2026-2826 · 3 Sept
- Drupal Module: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
WID-SEC-W-2026-2943 · 3 Sept
- Drupal Extensions: Mehrere Schwachstellen
WID-SEC-W-2026-3041 · 3 Sept
- Drupal Module: Mehrere Schwachstellen
WID-SEC-W-2026-2686 · 3 Sept
Drupal at a glance
Drupal is a powerful open-source CMS used for complex and enterprise websites. Drupal ships regular core releases plus coordinated security advisories on scheduled windows; as an internet-facing CMS, prompt patching is essential — the project's security team is well organized, and so are attackers.
For admins the coordinated security releases are the rhythm: Drupal announces core and contributed-module advisories on set days, and past critical flaws (the Drupalgeddon class) were exploited within hours — apply security updates immediately. Keep to a supported Drupal version and track its end-of-life, since running an unsupported major is a serious exposure. Contributed modules are the usual attack surface — keep them minimal, current and from the project. Updates run database updates — back up first and test on staging. Keep the underlying PHP supported. After updating, verify the site and modules. Patchletter surfaces new Drupal releases and security advisories.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 11.4 | 11.4.9 | EOL 7 Jul 27 |
| 11.3 | 11.3.18 | EOL in 66 days |
| 10.6 | 10.6.18 | EOL in 66 days |
| 11.2 | 11.2.14 | End of Life |
| 10.5 | 10.5.12 | End of Life |
| 10.4 | 10.4.10 | End of Life |
| 11.1 | 11.1.10 | End of Life |
| 11.0 | 11.0.13 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 11.4.9 | STABLE | 09/10/2026 | – |
| 11.4.8 | STABLE | 26/09/2026 | – |
| 11.4.7 | STABLE | 16/09/2026 | – |
| 11.4.6 | STABLE | 03/09/2026 | – |
| 11.4.5 | STABLE | 06/08/2026 | – |
| 11.4.4 | STABLE | 15/07/2026 | – |
| 11.4.3 | STABLE | 14/07/2026 | – |
| 11.4.2 | STABLE | 10/07/2026 | – |
| 11.4.1 | STABLE | 03/07/2026 | – |
| 11.3.18 | STABLE | 28/09/2026 | – |
| 11.3.17 | STABLE | 16/09/2026 | – |
| 11.3.16 | STABLE | 23/07/2026 | – |
| 11.3.14 | STABLE | 15/07/2026 | – |
| 11.3.13 | STABLE | 23/06/2026 | – |
| 11.2.14 | STABLE | 17/06/2026 | – |
| 11.1.10 | STABLE | 20/05/2026 | – |
| 11.0.13 | STABLE | 19/03/2025 | – |
| 10.6.18 | STABLE | 26/09/2026 | – |
| 10.6.17 | STABLE | 16/09/2026 | – |
| 10.6.16 | STABLE | 03/09/2026 | – |
| 10.6.15 | STABLE | 06/08/2026 | – |
| 10.6.14 | STABLE | 23/07/2026 | – |
| 10.6.13 | STABLE | 15/07/2026 | – |
| 10.6.12 | STABLE | 23/06/2026 | – |
| 10.5.12 | STABLE | 17/06/2026 | – |
| 10.4.10 | STABLE | 20/05/2026 | – |
| 10.3.14 | STABLE | 19/03/2025 | – |
| 10.2.12 | STABLE | 22/11/2024 | – |
| 10.1.8 | STABLE | 16/01/2024 | – |
| 10.0.11 | STABLE | 19/09/2023 | – |
| 9.5.11 | STABLE | 19/09/2023 | – |
| 9.4.15 | STABLE | 03/05/2023 | – |
| 9.3.22 | STABLE | 28/09/2022 | – |
| 9.2.21 | STABLE | 10/06/2022 | – |
| 9.1.15 | STABLE | 24/11/2021 | – |
| 9.0.14 | STABLE | 25/05/2021 | – |
| 8.9.20 | STABLE | 17/11/2021 | – |
| 8.8.12 | STABLE | 25/11/2020 | – |
| 7.103 | LTS | 04/12/2024 | – |
Frequently asked questions
- What is the latest version of Drupal?
- Drupal 11.4.9, released 09/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Drupal release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Drupal updates?
- Tick Drupal off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Drupal version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Drupal version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/drupal)https://patchletter.com/badge/drupal.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).