Drupal has released an advisory to address vulnerabilities in Drupal core 8.x versions prior to 8.1.10. Exploitation of one of these vulnerabilities could allow a remote attacker to take control of an affected system.
Users and administrators are encouraged to review Drupal’s Security Advisory and apply the necessary update.