Drupal 8.x — End of Life
EOL Actively exploitedDrupal 8.x reached end of life on Nov 2, 2021, 1800 days ago, and no longer receives security fixes. The most recent release in this series is 8.9.20. 10 CVEs are tracked for this series, including 1 critical and 1 actively exploited according to CISA KEV. 9 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Drupal 9. See Drupal 9 →
Drupal 8.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 8.9 | Jun 3, 2020 | Dec 1, 2020 | Nov 2, 2021 | 8.9.20 | EOL | |
| 8.8 | Dec 4, 2019 | Jun 3, 2020 | Dec 1, 2020 | 8.8.12 | EOL |
CVEs affecting Drupal 8.x (17)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-55808 | MEDIUM | 5.4 | 0.27% | — | 8.9 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core… | Jul 10, 2026 |
| CVE-2026-55808 | MEDIUM | 5.4 | 0.27% | — | 8.8 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core… | Jul 10, 2026 |
| CVE-2026-55807 | LOW | 3.1 | 0.22% | — | 8.9 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af… | Jul 10, 2026 |
| CVE-2026-55807 | LOW | 3.1 | 0.22% | — | 8.8 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af… | Jul 10, 2026 |
| CVE-2026-55806 | MEDIUM | 5.9 | 0.33% | — | 8.8 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is… | Jul 10, 2026 |
| CVE-2026-55806 | MEDIUM | 5.9 | 0.33% | — | 8.9 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is… | Jul 10, 2026 |
| CVE-2026-55804 | MEDIUM | 5.9 | 0.35% | — | 8.8 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | Jul 10, 2026 |
| CVE-2026-55804 | MEDIUM | 5.9 | 0.35% | — | 8.9 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | Jul 10, 2026 |
| CVE-2026-55803 | MEDIUM | 5.9 | 0.35% | — | 8.8 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | Jul 10, 2026 |
| CVE-2026-55803 | MEDIUM | 5.9 | 0.35% | — | 8.9 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | Jul 10, 2026 |
| CVE-2026-9082 | CRITICAL | 9.8 | 15.70% | KEV | 8.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core… | May 20, 2026 |
| CVE-2026-6366 | MEDIUM | 6.6 | 0.41% | — | 8.9 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | May 19, 2026 |
| CVE-2026-6366 | MEDIUM | 6.6 | 0.41% | — | 8.8 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | May 19, 2026 |
| CVE-2026-6365 | MEDIUM | 6.1 | 0.29% | — | 8.9 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core… | May 19, 2026 |
| CVE-2026-6365 | MEDIUM | 6.1 | 0.29% | — | 8.8 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core… | May 19, 2026 |
| CVE-2021-41164 | HIGH | 8.2 | 1.34% | — | 8.9 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advance… | Nov 17, 2021 |
| CVE-2020-9281 | MEDIUM | 6.1 | 4.30% | — | 8.8 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attacke… | Mar 7, 2020 |
Drupal 8.x is EOL — migrate to Drupal 9.x
Drupal 9.x is the next major release. Plan your upgrade before Drupal 8.x stops receiving security patches.
Add a Drupal 8 EOL badge to your README
Show your users which Drupal version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/drupal/8)Frequently asked questions
Is Drupal 8 end of life?
Yes. All Drupal 8.x releases have reached end of life and no longer receive security patches. There are 10 known CVEs affecting Drupal 8.x, including 1 critical. Migrate to Drupal 9.x as soon as possible.
What CVEs affect Drupal 8?
There are 10 CVEs tracked for Drupal 8.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Drupal 8 version?
The latest Drupal 8.x patch release is 8.9.20, released on November 17, 2021. Always run the latest patch to benefit from all security fixes.
How to migrate from Drupal 8 to Drupal 9?
To migrate from Drupal 8 to Drupal 9: (1) review the official Drupal 9 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Drupal 8 in production?
No. Drupal 8 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Drupal 8.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
