Drupal 9.x — End of Life

EOL Actively exploited
EOL: Nov 1, 20236 releases in this series18 CVEs

Drupal 9.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
9.5Dec 15, 2022Jun 21, 2023Nov 1, 20239.5.11EOL
9.4Jun 15, 2022Dec 14, 2022Jun 21, 20239.4.15EOL
9.3Dec 8, 2021Jun 15, 2022Dec 14, 20229.3.22EOL
9.2Jun 16, 2021Dec 8, 2021Jun 15, 20229.2.21EOL
9.1Dec 2, 2020Jun 16, 2021Dec 8, 20219.1.15EOL
9.0Jun 3, 2020Dec 2, 2020Jun 16, 20219.0.14EOL

CVEs affecting Drupal 9.x (18)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-9082CRITICAL9.810.40% KEV 9.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 9.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 9.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 9.4Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.810.40% KEV 9.0Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-6366MEDIUM6.60.08%9.3Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%9.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%9.0Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%9.4Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%9.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.08%9.5Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%9.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%9.5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%9.2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%9.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%9.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.05%9.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026

Drupal 9.x is EOL — migrate to Drupal 10.x

Drupal 10.x is the next major release. Plan your upgrade before Drupal 9.x stops receiving security patches.

See Drupal 10.x

Frequently asked questions

Is Drupal 9 end of life?

Yes. All Drupal 9.x releases have reached end of life and no longer receive security patches. There are 18 known CVEs affecting Drupal 9.x, including 6 critical. Migrate to Drupal 10.x as soon as possible.

What CVEs affect Drupal 9?

There are 18 CVEs tracked for Drupal 9.x, including 6 critical severity issues and 6 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Drupal 9 version?

The latest Drupal 9.x patch release is 9.5.11, released on September 19, 2023. Always run the latest patch to benefit from all security fixes.

How to migrate from Drupal 9 to Drupal 10?

To migrate from Drupal 9 to Drupal 10: (1) review the official Drupal 10 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Drupal 9 in production?

No. Drupal 9 has reached end of life and security vulnerabilities are no longer patched. Critically, 6 CVEs affecting Drupal 9.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA