Review the latest advisories
The Incident Response team sends advisories about security vulnerabilities to U of T’s technical staff. If you have questions or concerns, contact security.response@utoronto.ca.

The advisories published here focus on those we feel are most relevant to the university environment but should not be considered an exhaustive list. The Canadian Centre for Cyber Security publishes advisories on potential and imminent cyber threats and vulnerabilities and provides a more comprehensive list of advisories.
July 24, 2026
Researchers have identified two vulnerabilities in WordPress Core dubbed ‘wp2shell’ which can allow unauthenticated attackers to gain remote code execution on default WordPress installations.
July 24, 2026
A flaw in the Linux kernel lets any user with an ordinary, non-privileged login take complete control of the system as root.
July 24, 2026
On July 21, 2026, F5 disclosed and patched CVE-2026-42533, a critical-severity heap-based buffer overflow vulnerability affecting various versions of NGINX.
July 22, 2026
Zoom has released fixes for a critical vulnerability, tracked as CVE-2026-53412 (CVSS 9.8), affecting the Zoom Workplace desktop client.
July 15, 2026
On May 7, 2026, security researcher Hyunwoo Kim (@v4bel on GitHub) published a technical report detailing Dirty Frag, a Linux local privilege escalation (LPE) vulnerability class.
May 11, 2026
On May 7, 2026, security researcher Hyunwoo Kim (@v4bel on GitHub) published a technical report detailing Dirty Frag, a Linux local privilege escalation (LPE) vulnerability class.
April 30, 2026
We’ve been notified of this local privilege escalation vulnerability, in Linux kernel 4.14 (introduced in 2017), that affects most flavours of Linux.
April 22, 2026
A critical unauthenticated Remote Code Execution (RCE) vulnerability has been identified in the Ninja Forms – File Uploads extension for WordPress.
March 17, 2026
Qualys Threat Research Unit (TRU) disclosed a set of nine vulnerabilities in Linux AppArmor, collectively named "CrackArmor".
February 4, 2026
In late January 2026, security researchers at DepthFirst discovered a flaw in OpenClaw – formerly known as Moltbot and Clawdbot – only a few months after the platform’s rapid rise in popularity.
December 4, 2025
Multiple NPM packages were compromised in late 2025 through account takeovers and malicious code injections.
December 4, 2025
A critical remote code execution vulnerability (CVE-2025-55182) has been found in React Server Components and in widely used frameworks such as Next.js.
