Drupal 11.x — End of Life

EOL soon Actively exploited
EOL: Dec 16, 2026in 189d4 releases in this series13 CVEs

Drupal 11.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
11.3Dec 17, 2025Jun 16, 2026Dec 16, 202611.3.11Active
11.2Jun 18, 2025Dec 10, 2025Jun 17, 202611.2.13EOL soon
11.1Dec 16, 2024Jun 18, 2025Dec 10, 202511.1.10EOL
11.0Aug 2, 2024Dec 16, 2024Jun 16, 202511.0.13EOL

CVEs affecting Drupal 11.x (13)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-9082CRITICAL9.810.40% KEV 11.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 11.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 11.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 11.0Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-6366MEDIUM6.60.08%11.0Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%11.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%11.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%11.3Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6367MEDIUM6.10.03%11.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%11.2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%11.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%11.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%11.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026

Frequently asked questions

Is Drupal 11 end of life?

Partially. Some Drupal 11.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Drupal 11?

There are 13 CVEs tracked for Drupal 11.x, including 4 critical severity issues and 4 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Drupal 11 version?

The latest Drupal 11.x patch release is 11.3.11, released on May 28, 2026. Always run the latest patch to benefit from all security fixes.

When was Drupal 11 first released?

Drupal 11.0 was initially released on December 17, 2025. See the full version timeline in the table above.

Is it safe to run Drupal 11 in production?

Drupal 11 is still supported and safe for production use until December 16, 2026. Ensure you are running the latest patch version (11.3.11) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA