Drupal 8.x — End of Life

EOL Actively exploited
EOL: Nov 2, 20212 releases in this series10 CVEs

Drupal 8.x reached end of life on Nov 2, 2021, 1800 days ago, and no longer receives security fixes. The most recent release in this series is 8.9.20. 10 CVEs are tracked for this series, including 1 critical and 1 actively exploited according to CISA KEV. 9 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Drupal 9. See Drupal 9 →

Drupal 8.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
8.9Jun 3, 2020Dec 1, 2020Nov 2, 20218.9.20EOL
8.8Dec 4, 2019Jun 3, 2020Dec 1, 20208.8.12EOL

CVEs affecting Drupal 8.x (17)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-55808MEDIUM5.40.27%—8.9Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55808MEDIUM5.40.27%—8.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55807LOW3.10.22%—8.9Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55807LOW3.10.22%—8.8Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.33%—8.8URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.33%—8.9URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.35%—8.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.35%—8.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.35%—8.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.35%—8.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-9082CRITICAL9.815.70% KEV 8.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-6366MEDIUM6.60.41%—8.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.41%—8.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6365MEDIUM6.10.29%—8.9Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.29%—8.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2021-41164HIGH8.21.34%—8.9CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advance…Nov 17, 2021
CVE-2020-9281MEDIUM6.14.30%—8.8A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke…Mar 7, 2020

Drupal 8.x is EOL — migrate to Drupal 9.x

Drupal 9.x is the next major release. Plan your upgrade before Drupal 8.x stops receiving security patches.

See Drupal 9.x

Add a Drupal 8 EOL badge to your README

Show your users which Drupal version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Drupal 8 EOL status
[![Drupal 8 EOL status](https://eolcanary.com/badge/drupal/8.svg)](https://eolcanary.com/explore/drupal/8)

Frequently asked questions

Is Drupal 8 end of life?

Yes. All Drupal 8.x releases have reached end of life and no longer receive security patches. There are 10 known CVEs affecting Drupal 8.x, including 1 critical. Migrate to Drupal 9.x as soon as possible.

What CVEs affect Drupal 8?

There are 10 CVEs tracked for Drupal 8.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Drupal 8 version?

The latest Drupal 8.x patch release is 8.9.20, released on November 17, 2021. Always run the latest patch to benefit from all security fixes.

How to migrate from Drupal 8 to Drupal 9?

To migrate from Drupal 8 to Drupal 9: (1) review the official Drupal 9 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Drupal 8 in production?

No. Drupal 8 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Drupal 8.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA