Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Drupal · AUTOMATIC DISCOVERY

Drupal Product policy

Drupal is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Drupal is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductDrupal
ReleaseProduct policy
End of Support9 December 2026
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2026-9082Added 22 May 2026

Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Drupal · CoreRansomware use: Unknown

CISA entry
CVE-2018-7602Added 13 Apr 2022

Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

Drupal · CoreRansomware use: Known

CISA entry
CVE-2019-6340Added 25 Mar 2022

Drupal Core Remote Code Execution Vulnerability

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

Drupal · CoreRansomware use: Unknown

CISA entry
CVE-2020-13671Added 18 Jan 2022

Drupal core Un-restricted Upload of File

Improper sanitization in the extension file names is present in Drupal core.

Drupal · Drupal coreRansomware use: Unknown

CISA entry
CVE-2018-7600Added 3 Nov 2021

Drupal Core Remote Code Execution Vulnerability

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

Drupal · Drupal CoreRansomware use: Known

CISA entry

Package vulnerability advisories

Checked 9 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2026-55805Unknown severity

Vulnerability advisory

pkg:composer/drupal/coreFixed: 10.6.13, 11.3.14, 11.4.4, 11.1.0, 11.2.0, 11.3.0

OSV record
CVE-2026-15916Unknown severity

Vulnerability advisory

pkg:composer/drupal/coreFixed: 10.6.13, 11.3.14, 11.4.4, 11.1.0, 11.2.0, 11.3.0

OSV record

Source evidence

PRIMARYManual

Drupal official lifecycle source

Drupal 12 will be released on the week of December 7, 2026. Contributions to related issues will help ensure that we meet our goals. | Drupal 10 end of life | Drupal 10.6.0 is the last minor release of Drupal 10. | Drupal 10 will reach end of life on December 9, 2026. This is the same week that Drupal 12 will be released. No new releases of Drupal 10 will be made after this date. | Drupal 7 end of life | Drupal 7 is now end of life. Supported ended on January 5, 2025. | Read the security advisory for more details: End of life announcement and changes to Drupal 7 support - PSA-2023-06-07 . Check out the Drupal 7 end of life resource center for migration and long term support options.

Publisher identity used by product-specific official-source collectors.

First collected 27 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source