Security releaseDrupal core advisory SA-CORE-2026-008 — managed clients already patched.Read the advisory
websitesupport.io
Resources

Security alerts

Verified CVE advisories and patch status across Drupal, WordPress, Magento, Shopify, Strapi and Contentful.

CriticalScore: 20/25DrupalSA-CORE-2026-008

Drupal core — access bypass

Unauthenticated access bypass affecting Drupal 10.3–11.1. Patch to 10.3.14 / 10.4.6 / 11.1.4 immediately.

30 May 2026
Patched for managed clients
HighScore: 15/25WordPressWP-2026-0512

WordPress — popular plugin RCE

Two widely-used plugins shipped urgent fixes. Update affected plugins across all instances now.

19 May 2026
Patched for managed clients
HighScore: 16/25MagentoAPSB26-22

Adobe Commerce — XSS in admin

Stored XSS in the admin panel. Apply the latest Adobe Commerce security patch and rotate admin sessions.

12 May 2026
Mitigation available
MediumScore: 11/25DrupalSA-CONTRIB-2026-041

Drupal contrib — Views access

A contributed module exposes unpublished content via a Views endpoint under specific configs.

4 May 2026
Patched for managed clients
MediumScore: 10/25StrapiCVE-2026-3318

Strapi — privilege escalation

An authenticated user could escalate permissions via the admin API. Upgrade to the latest v5 patch.

27 Apr 2026
Patched for managed clients
LowScore: 6/25ShopifySHOP-2026-118

Shopify app — token leakage

A third-party app could leak storefront tokens in logs. Rotate tokens and update the app.

20 Apr 2026
Advisory

Never patch late again

Managed clients are patched within SLA — typically the same day a critical advisory is published, often before it's public.

Stay ahead of the next release

Security alerts, platform updates and industry analysis — straight to your inbox.

We respect your privacy and only send essential updates.