On 8 September 2026, the TYPO3 team published security releases for all supported versions: 14.3.7 and 13.4.35 as LTS versions as well as 12.4.49, 11.5.54 and 10.4.60 for installations with extended support (ELTS). Release notes for TYPO3 13.4.35
What was fixed
The release includes two security advisories. The first concerns all the version branches mentioned above: several AJAX routes of the translation wizard in the backend did not check permissions. Logged-in editors could use them to retrieve information for which they lacked the rights. The severity is rated as medium. Security advisory TYPO3-CORE-SA-2026-022
The second advisory concerns TYPO3 14 only: there, administrators without system maintainer rights could schedule configuration commands and thus change settings that are actually reserved for maintainers. Anyone using TYPO3 13 is not affected. Security advisory TYPO3-CORE-SA-2026-023
How urgent is the update?
Both vulnerabilities require a valid backend account; anonymous access from the web is not sufficient. How urgent the update is for an installation depends on who has access there and which rights these accounts have – correspondingly more so for systems with many editorial accounts or external access. We recommend scheduling the update promptly.
Also take extensions into account
Independently of the TYPO3 core, a security update for the Mask extension was released on 25 August. The vulnerability reported there was fixed in versions 8.3.12 and 9.0.11. If Mask is used, the installed extension version should therefore also be checked. Security advisory on Mask
Anyone who does not want to install such updates themselves will find ongoing support under Maintenance and support. If a version change is coming up anyway, our page on the TYPO3 upgrade describes the procedure.



