Drupal is warning users that it’s preparing a patch for a ‘highly critical’ vulnerability that may be exploited shortly after its disclosure.

Drupal plans May 20 core security patches as exploits may follow within hours or days, requiring urgent site updates.

The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches