Drupal core security releases happen on scheduled Wednesdays, typically the third Wednesday of the month. This regular cadence lets site operators plan update windows in advance.
Security advisories are published on Drupal.org with details about the severity, affected versions, and mitigation. Critical issues are sometimes released outside the normal window if the situation warrants immediate action.
Contrib modules follow a similar process, with the security team coordinating fixes with maintainers. Subscribe to the security mailing list at Drupal.org to receive advisories as they are published. Applying security updates promptly is essential because vulnerabilities are often exploited within days or even hours of public disclosure. The security team’s work is one of the reasons Drupal is trusted by organisations that cannot afford compromises, including governments and universities worldwide.