Drupal.org published a batch of 26 security advisories covering 25 contributed modules on Wednesday, October 7, 2026. One is rated highly critical and seven are critical. Drupal core is not affected. It concerns any Drupal site that has one of those modules installed, whatever its size.
What we know
- What shipped and when: 26 advisories, SA-CONTRIB-2026-192 through SA-CONTRIB-2026-217, all dated October 7, 2026, according to drupal.org's list of advisories for contributed projects. They cover 25 projects: Authenticator Login Plus (2FA) gets two.
- Severity, on Drupal's own scale: 1 highly critical, 7 critical, 17 moderately critical and 1 less critical.
- The most serious one: Block AJAX, scored 20 out of 25. According to its advisory, the worst case is code running on the server, and it only affects sites with Layout Builder enabled, or another block plugin that handles that data unsafely. Version 3.0.2 fixes it. The advisory points to the release notes for potentially breaking changes.
- Two modules lose support: ECA Helper and Orphans Media. Drupal says each has a known security issue the maintainer has not fixed, and that anyone using them should uninstall them. There is no fixed version.
- The most widely installed: Easy Breadcrumb (more than 106,000 sites report using it), Menu Link Attributes (more than 91,000) and Leaflet (nearly 31,000), according to each project page on drupal.org, read on October 8. All three are moderately critical, and their advisories list conditions: a specific setting, menu administration permissions, or permission to edit content.
- Two-factor login: two 2FA modules are on the list. In Authenticator Login Plus (2FA), according to its advisories, a user could get in without the second factor in two situations. In Two Factor Authentication – TFA / Passwordless Login, an API key stored on the site could be disclosed when the headless mode was turned on.
- Exploitation: all 26 advisories carry "Theoretical" in the exploit field of the risk score. On Drupal's scale that is the lowest value: no public exploit code and no public documentation on how to build one.
- Core: none of the 26 is a Drupal core advisory. The latest one for core is SA-CORE-2026-013, from September 16, according to drupal.org's list.
The 25 modules, with the fixed version each advisory gives:
| Module | Severity | Fixed version |
|---|---|---|
| Block AJAX | Highly critical | 3.0.2 |
| ECA Helper | Critical | No fix: uninstall |
| Orphans Media | Critical | No fix: uninstall |
| Entity Reference Manager (Merge entities) | Critical | 1.0.3 |
| MathJax: LaTeX for Drupal | Critical | 4.1.2 |
| Actstream | Critical | 2.0.1 or 2.1.1 |
| Restrict route by IP | Critical | 1.3.1 or 2.0.1 |
| Authenticator Login Plus (2FA) | Critical and moderately critical (2 advisories) | 1.0.1 |
| Easy Breadcrumb | Moderately critical | 2.0.11 |
| Menu Link Attributes | Moderately critical | 8.x-1.8 |
| Leaflet | Moderately critical | 10.4.13 |
| Linked Field | Moderately critical | 8.x-1.8 |
| Permissions by Term | Moderately critical | 3.1.41 |
| Gutenberg | Moderately critical | 8.x-2.15 or 3.0.7 |
| Country | Moderately critical | 2.1.3 or 2.2.1 |
| Two Factor Authentication – TFA / Passwordless Login | Moderately critical | 5.4.1 or 5.5.2 |
| Xray Audit | Moderately critical | 1.6.3, 2.0.4 or 3.1.1 |
| DKAN | Moderately critical | 4.0.4 or 4.1.5 |
| Inline Formatter Field | Moderately critical | 4.2.0 |
| Inline Entity Form Dialog | Moderately critical | 1.0.6 |
| Views Share | Moderately critical | 2.0.1 |
| SmartLinker AI | Moderately critical | 1.0.3 |
| Freelinking | Moderately critical | 4.0.3 |
| Advanced Filesystem | Moderately critical | 1.0.28 |
| Examples for Developers | Less critical | 4.0.7 |
Where several versions are listed, each one belongs to a different branch of the module.
What changes and what doesn't
What changes: since October 7, 25 modules have publicly described flaws, 23 with a fixed version and 2 without one. A site that runs one of them and does not update is left with a known issue.
Nothing changes for a Drupal site that has none of these modules. There is no core update in this batch.
Severity is not the whole story. Almost every advisory comes with conditions: a setting someone had to turn on, a permission, a submodule. Easy Breadcrumb, the most installed of the 25, is only affected when the "Add parent hierarchy" option is on and a parent term is unpublished, according to its advisory. Being in the table does not mean your site is exposed. That reading is this article's: each advisory simply says to install the latest version.
How to tell if you're affected
You are affected if your site runs Drupal and uses any of the 25 modules. Seven steps:
- Open the updates report. In the admin area, go to Reports → Available updates (the path is /admin/reports/updates). Drupal flags affected modules with "Security update required!". If the page is missing, the core update module is not enabled.
- Compare it with the table. On a Composer-managed site, `composer show "drupal/*"` lists every module with its version.
- Start with the serious ones. Block AJAX first if you use Layout Builder. Then the two 2FA modules and the rest of the critical ones.
- Remove what lost support. ECA Helper and Orphans Media will not get a patch. Before uninstalling them, check which parts of the site depend on them.
- Back up, then update. Copy the files and the database. Then update the module, run the database updates (with `drush updatedb` or at /update.php) and clear the cache. The Menu Link Attributes advisory asks for the database updates explicitly.
- Check the cases with an extra step. MathJax: after updating, look at the status report in case it warns that safe mode is not enabled. Examples for Developers: uninstall the `email_example` submodule immediately. Authenticator Login Plus: users who had turned 2FA off will be asked to set it up again.
- If someone else maintains your site, ask: "Do we use any of the 25 modules in Drupal's October 7 advisories? Which versions are we on?"
After updating, test the home page, the menus, the forms and the login.
Related: Drupal Web Development by Experts
Sources
- Drupal.org, "Security advisories for contributed projects", the list with the 26 advisories of October 7, 2026
- Drupal.org, SA-CONTRIB-2026-192, Block AJAX
- Drupal.org, SA-CONTRIB-2026-193, ECA Helper, and SA-CONTRIB-2026-196, Orphans Media: https://www.drupal.org/sa-contrib-2026-193 and https://www.drupal.org/sa-contrib-2026-196
- Drupal.org, SA-CONTRIB-2026-197 and SA-CONTRIB-2026-201, Authenticator Login Plus (2FA): https://www.drupal.org/sa-contrib-2026-197 and https://www.drupal.org/sa-contrib-2026-201
- Drupal.org, SA-CONTRIB-2026-207, Two Factor Authentication – TFA / Passwordless Login
- Drupal.org, SA-CONTRIB-2026-212, Easy Breadcrumb
- Drupal.org, SA-CONTRIB-2026-209, Menu Link Attributes
- Drupal.org, "Security risk levels defined", the severity scale
- Drupal.org, security advisories for Drupal core
Updates: this article will be updated if Drupal changes the severity of an advisory, if exploitation of any of them is confirmed, or if ECA Helper or Orphans Media get a new maintainer.