08/26/2026
If you maintain a Drupal site, here is your to-do list from today's security releases. Fourteen advisories, all contrib, nothing for core.
Check your installed modules against this list and update whatever matches:
Entity API to 1.8.0
Blazy to 3.0.18
Slick Carousel to 2.1.0
Content Moderation Notifications to 3.9.0
Commerce CyberSource to 1.10.0
DXPR Builder to 2.8.1
Data field to 2.0.13
Digital Signage Framework to 2.6.1
Disable Login Page to 1.1.4
Entity PDF to 2.1.5
LDAP / Active Directory Integration to 2.2.1
Address Suggestion to 1.0.25
CAPTCHA Protected Page to 1.0.2
Monster Menus to 9.5.3
Thirteen are rated moderately critical. Blazy is less critical. Monster Menus is a Drupal 9 release; the rest are for 10 and 11.
Start with Entity API if it shows up in your composer file. It is a common dependency, so plenty of sites are running it without anyone having deliberately installed it, and an information disclosure bug in something that quiet is easy to leave sitting there.
Nothing on this list applies to modules you don't have installed, so a short audit is all most sites need.