‘Highly critical’ Drupal security flaw prompts urgent patch

The message from the developers is simple: Drop everything and patch now.

A highly critical security patch was released on Wednesday for the popular Drupal content management system, which powers some of the world’s most visited websites.

The message from the developers is simple: Drop everything and patch now.

The new update fixes a remote code execution vulnerability that “potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.”


All it takes is for an anonymous user to visit a targeted page and they can see, modify and delete private data. No attacks have been detected yet, but the Drupal team and experts believe they will commence in short order.

Given the severity of the issue, the Drupal team has provided updates to older versions of the software it had stopped supporting.

The vulnerability was discovered by Jasper Mattsson, an employee of Drupal security auditing firm Druid.

The bug is being called Drupalgeddon2.


The first iteration of Drupalgeddon came in 2014 when a bug allowed attackers to take over a target. Independent journalist Kim Zetter reported in 2017 that years after a patch was available, an election security security center in Georgia had been attacked via the vulnerability.

Patrick Howell O'Neill

Written by Patrick Howell O'Neill

Patrick Howell O’Neill is a cybersecurity reporter for CyberScoop based in San Francisco.

Latest Podcasts