Drupal 10.x — End of Life

EOL soon Actively exploited
EOL: Dec 16, 2026in 190d7 releases in this series21 CVEs

Drupal 10.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
10.6Dec 17, 2025Jun 16, 2026Dec 16, 202610.6.10Active
10.5Jun 18, 2025Dec 17, 2025Jun 17, 202610.5.11EOL soon
10.4Dec 17, 2024Jun 18, 2025Dec 10, 202510.4.10EOL
10.3Jun 20, 2024Aug 2, 2024Jun 16, 202510.3.14EOL
10.2Dec 15, 2023Jun 20, 2024Dec 17, 202410.2.12EOL
10.1Jun 22, 2023Dec 15, 2023Jun 20, 202410.1.8EOL
10.0Dec 15, 2022Jun 21, 2023Dec 15, 202310.0.11EOL

CVEs affecting Drupal 10.x (21)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-9082CRITICAL9.810.40% KEV 10.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 10.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 10.0Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 10.4Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 10.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 10.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 10.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-6366MEDIUM6.60.08%10.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%10.5Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%10.4Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%10.3Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%10.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%10.0Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%10.6Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.6Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%10.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026

Drupal 10.x will reach end of life — migrate to Drupal 11.x

Drupal 11.x is the next major release. Plan your upgrade before Drupal 10.x stops receiving security patches.

See Drupal 11.x

Frequently asked questions

Is Drupal 10 end of life?

Partially. Some Drupal 10.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Drupal 10?

There are 21 CVEs tracked for Drupal 10.x, including 7 critical severity issues and 7 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Drupal 10 version?

The latest Drupal 10.x patch release is 10.6.10, released on May 28, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Drupal 10 to Drupal 11?

To migrate from Drupal 10 to Drupal 11: (1) review the official Drupal 11 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Drupal 10 in production?

Drupal 10 is still supported and safe for production use until December 16, 2026. Ensure you are running the latest patch version (10.6.10) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA