Four security fixes out for Umbraco 17 and 18
Umbraco released security patches today, 6 October 2026, for four vulnerabilities in Umbraco CMS 17 and 18. None of them is rated high, and three of the four need someone to already be logged in to the backoffice, so this is not a drop-everything moment. It is still a patch worth applying this week, and if we manage your site on Umbraco Cloud, you do not need to do anything.
The advisory covers Umbraco CMS 17.0.0 to 17.7.0 and 18.0.0 to 18.2.0. The fixes ship in 17.7.1 and 18.2.1.
Umbraco 13 is not named in this advisory. That is good news for anyone still on 13, but it is not a reason to relax: security support for Umbraco 13 ends on 14 December 2026, and after that there will be no patch at all when the next advisory lands. If your site is still on 13, the time to plan the upgrade is now, not after the first unpatched advisory.
Content access restrictions not fully enforced (moderate). Some of the backoffice's content version features did not check permissions properly. A logged-in editor with access to the Content section could view content they had not been granted access to. If you use user groups and start nodes to keep certain teams out of certain parts of the site, this is the one that matters.
Restricted users could delete media outside their area (moderate). A backoffice user whose media permissions were limited to one part of the media library could cause files elsewhere in the library to be deleted. Nothing is exposed, but losing images and documents from live pages is its own kind of incident.
File upload type restrictions could be bypassed (low). A weakness in how file names were validated meant the configured list of allowed or blocked file types could be sidestepped during backoffice uploads. Again, this needs a valid backoffice login.
Real-time backoffice endpoints reachable without logging in (low). Some of the real-time communication endpoints the backoffice uses could be reached without authentication, exposing limited information about editorial activity. This is the only one of the four that does not need a login, and it is also the least serious.
It is tempting to read "authenticated users only" as "not a real risk". It is a smaller risk, not no risk. Most sites have more backoffice accounts than they think, including old agency logins, ex-staff who were never removed, and shared accounts with weak passwords. Any of those becomes a route to content someone should not see, or to deleting media they should not touch. If you have not reviewed who has backoffice access recently, this is a good prompt to do it, patch or no patch.
If your site is on Umbraco Cloud, Umbraco is rolling out the upgrade automatically today. No action needed. That covers every Cloud site we manage.
If your site is self-hosted, someone needs to upgrade it to 17.7.1 or 18.2.1. Umbraco is clear that upgrading is the only complete fix and there is no configuration change that fully resolves these issues. It is a patch release rather than a major version jump, so on a well-kept site it is a quick, low-risk update. Until it is done, the sensible stopgaps are limiting backoffice access to people you trust and making sure file uploads are governed by an explicit list of allowed extensions rather than a list of blocked ones.
If you are not sure which version you are running, or whether you are on Cloud at all, your technical contact should be able to tell you in a couple of minutes.
We have already checked. Every site we manage on Umbraco Cloud is covered by today's automatic rollout, and we are applying the patch to the self-hosted sites in our care rather than waiting to be asked. If yours is one of them and you want confirmation in writing, just reply and we will tell you the exact version you are running and when it was patched.
If you run Umbraco 17 or 18 somewhere we do not manage and want a hand getting it patched, or you are on 13 and want to talk about the upgrade before December, get in touch.
Tell us what you're working on and we'll come back within one working day.
An Umbraco Silver Partner agency in Llandudno, North Wales and the Isle of Man, building and looking after Umbraco and .NET websites for businesses and agencies across the UK and beyond. Simon Antony is a brand of Simplepage Ltd.
Maesgwyn, 3 Claremont rd,
Llandudno, North Wales, LL30 2UF