Drupal Just Gave Three Modules the Unsupported Stamp

Drupal Just Gave Three Modules the Unsupported Stamp

Nothing ends a relationship faster than radio silence, and three Drupal contrib modules just got ghosted so hard the security team had to step in and make it official. As of August 19, Screenshot, Link content parser, and Gammu SMS Daemon are all wearing the scarlet "Unsupported" badge — Drupal's way of saying "we know about the hole, and nobody's coming to patch it."

Three Modules, Zero Fixes, One Bad Week

The Drupal Security Team published critical advisories for all three projects on the same day: SA-CONTRIB-2026-102 for Screenshot (CVE-2026-76759, CVE-2026-76782), SA-CONTRIB-2026-101 for Link content parser (CVE-2026-76758), and SA-CONTRIB-2026-100 for Gammu SMS Daemon (CVE-2026-76755 through 76757). Every one is rated Critical at 16 out of 25 on Drupal's risk scale.

"Unsupported" isn't a routine label — it's what happens when a known, serious vulnerability sits unpatched long enough that the security team stops covering the module altogether. It's the digital equivalent of a landlord condemning a building instead of fixing the wiring.

Why "It Still Works" Isn't the Same as "It's Safe"

Here's the trap: none of these modules stopped functioning. Sites running them look and behave exactly the same today as they did last week, which is exactly why unsupported-module risk is so easy to ignore until it isn't. A module with no maintainer patching a known critical flaw is a standing invitation, not a dormant risk.

This lands right after five more moderately critical advisories a week earlier covering access bypass and SSRF issues in modules like Commerce PayPal and Quick Tabs — a reminder that a Drupal site is only as secure as its least-loved dependency, and most sites are running at least one module nobody's thought about since the initial build.

If you don't know whether your site is running Screenshot, Link content parser, or Gammu SMS Daemon, that's the whole problem in one sentence.

We audit Drupal sites for exactly this kind of dependency rot — if you want a second set of eyes on what's quietly running unpatched on your site, grab our free supply-chain security checklist.

Source: Drupal.org Security Advisories