Should you be worried about the rise in high-severity Craft CMS security updates?
Craft has had a huge increase in security patches this year. But don't be alarmed, it's a sign of the times and that Craft is dealing with things responsibly.
Over the past year, Craft CMS has had an increase in the number of security advisories. In the first 8 months of 2026, there's more than the entirety of the past five years combined!
So, has something gone wrong here? Should site owners be worried about choosing Craft?
No. The numbers describe a changing world where AI is finding a lot more potential issues than humans alone ever could, but the story of the rise in issues also describe a process that's working well.
Vulnerabilities are being found, fixed, and patched and then shared after people have had enough time to update.
What matters is whether these fixes are being applied on your site in a timely and proper manner.
The numbers
There's been 74 security advisories between January and early August 2026 (compared to 53 in the previous 5 years).
Why 2026 has exploded
Craft hasn't suddenly become insecure, what's changed is how quickly people can find the bugs, flaws, and edge-cases that were there all along.
AI-assisted tools have matured quickly and researchers can now use these to find potential issues in hours rather than days and weeks. They aren't new issues, they're just newly discovered. Some of the 2026 advisories have affected all the way back to Craft CMS 4.0 from 2022.
This goes beyond Craft:
- FIRST (a forum for incident response teams) expect 46% more CVEs (Common Vulnerabilities and Exposures - the system for documenting security issues) than their original forecast
- In May, GitHub published 1,560 reviewed advisories - the highest month ever
- Linux (which powers most of the world's servers and personal devices including Android phones) had 432 CVEs over just two days!
- Patchstack identified 11,334 new vulnerabilities in the WordPress ecosystem in 2025, a 42% increase on 2024.
In short, this isn't a Craft problem - it's a phenomenon across the software landscape.
Isn't this a bad thing?
Every advisory is a bug that was found, fixed, and patched. It's the system doing its job and it's aligned with Craft's own security policy - basically:
- A researcher finds a bug
- They report it privately via Craft's proper procedures
- Craft reproduces the problem, and fixes it
- Craft releases a fix
- 30 days later an advisory is released, giving teams enough time to update it
By the time you read about a vulnerability, the fix has usually been available for a month.
So when this procedure works, it's great. Better than the world pre-AI because these things are getting found now.
But the scenario to worry about is when the procedure isn't followed. When attackers are finding flaws and using them quietly without disclosing them. With software security, it's always a race between bad agents and good guys to find bugs first. But as we can see, Craft is not standing still with finding and fixing.
Okay, but isn't "high severity" a concern?
It's not nothing, but if you're managing your site responsibly it's just another day at work in 2026!
Craft keeps a handy definition of what the severity levels mean, put into my own words:
- Critical: you've got a high chance of being compromised. Patch now, and make sure you're safe.
- High: there's a potential threat here, but the issue is difficult to exploit. Update within 30 days.
- Moderate: normally needs something else has been exploited first, eg: a problem with your server itself. Update within 90 days.
- Low: most little bits that don't pose an escalation risk or compromise data or systems. Patch when you can.
So what should we be doing?
Update, and stay vigilant. Your agency should be handling this for you (assuming you're actively engaged with them). Here at Mutual, we update sites on either a 14 or 30 day recurring rhythm, with Critical updates prioritised outside of that rhythm.
Our approach is updating little and often, it's easier to stay up to date with things if you don't let a site drift away. A bad scenario would be a critical update being released, but not being able to patch to it easily because you're 4 months behind on other updates.
Make sure your agency has mechanisms to be alerted about critical issues and that they have plans in place for how to deal with them. Make it their job to be on top of this.
If you are running and end of life version of Craft (that is Craft 1, Craft 2, Craft 3 or Craft 4) upgrade as soon as you can to Craft 6. A critical update could be released at any time, and running end of life software means you may not get a patch. Make sure your business as a whole sees this as an unacceptable risk. Upgrades can be harder than updates, so it may be a small project in its own right.
On your side, make sure as few people as possible have admin accounts. By our count, we think about half of 2026 advisories only worked if they already had a control panel account. Make sure staff that aren't using the CMS are removed, and that those who do have it have things like 2 Factor Authentication or Passkeys enabled (both are included out-of-the-box in Craft 5).
We're happy to help answer any questions you may have, just reach out - even if you're not our client - hello@mutual.agency.
Our methodology
We used AI to look at every reviewed advisory on the Craft CMS package on GitHub. The analysis and write-up was done by a human (me!). One caveat is that the 2022 figure includes older CVEs from 2017 to 2020 that we only added to the system that year.
If you spot any mistakes please just let me know and we'll correct.
Sources
Andrew is Technical Director at Mutual, a Craft CMS Partner agency. He has been building with Craft CMS since its public beta in 2012 — working through every major version from Craft 1 to Craft 5 — and has delivered over 100 sites for clients including Apple, Transparency International, and Arts University Bournemouth.
He writes about Craft CMS on the Mutual blog and has contributed to net Magazine. At Mutual, he leads development of Mutual One, a marketing platform built on Craft CMS as its foundation.
He has spoken about Craft CMS to undergraduate students at the University of Brighton and Canterbury Christ Church University, and appeared on the Devmode.fm podcast. He has also trained other developers on working with the platform.
More from The Journal
Can AI text help my Craft CMS website's performance?
Can you benefit from having AI create new content for your website? Let's dive in!
Redirects in Craft CMS without a plugin
Craft CMS now has built in redirects abilities, so you may not need a plugin for them in 2026.
How we make Craft CMS page builders in 2026
Our go-to technique for making page builders in 2026.