Review the latest advisories
The Incident Response team sends advisories about security vulnerabilities to U of T’s technical staff. If you have questions or concerns, contact security.response@utoronto.ca.

The advisories published here focus on those we feel are most relevant to the university environment but should not be considered an exhaustive list. The Canadian Centre for Cyber Security publishes advisories on potential and imminent cyber threats and vulnerabilities and provides a more comprehensive list of advisories.
August 7, 2026
WordPress has remediated a reflected cross-site scripting vulnerability in the login interface (wp-login.php) affecting all releases.
July 24, 2026
Broadcom has released security updates addressing five vulnerabilities affecting VMware ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and related Telco Cloud products.
July 24, 2026
Researchers have identified two vulnerabilities in WordPress Core dubbed ‘wp2shell’ which, when, chained together, can allow unauthenticated attackers to gain remote code execution on default WordPress installations.
July 24, 2026
A flaw in the Linux kernel lets any user with an ordinary, non-privileged login take complete control of the system as root. No special permissions or unusual configuration are needed.
July 24, 2026
On July 21, 2026, F5 disclosed and patched CVE-2026-42533, a critical-severity heap-based buffer overflow vulnerability affecting various versions of NGINX.
July 22, 2026
Zoom has released fixes for a critical vulnerability, tracked as CVE-2026-53412 (CVSS 9.8), affecting the Zoom Workplace desktop client for Windows, the Zoom VDI Client for Windows, and the Zoom Meeting SDK for Windows.
July 15, 2026
Critical Microsoft SharePoint Server vulnerabilities may allow privilege escalation, authentication bypass and remote code execution. Affected systems should be patched immediately.
May 11, 2026
On May 7, 2026, security researcher Hyunwoo Kim (@v4bel on GitHub) published a technical report detailing Dirty Frag, a Linux local privilege escalation (LPE) vulnerability class.
April 30, 2026
We’ve been notified of this local privilege escalation vulnerability, in Linux kernel 4.14 (introduced in 2017), that affects most flavours of Linux.
April 22, 2026
A critical unauthenticated Remote Code Execution (RCE) vulnerability has been identified in the Ninja Forms – File Uploads extension for WordPress.
March 17, 2026
Qualys Threat Research Unit (TRU) disclosed a set of nine vulnerabilities in Linux AppArmor, collectively named "CrackArmor".
February 4, 2026
In late January 2026, security researchers at DepthFirst discovered a flaw in OpenClaw – formerly known as Moltbot and Clawdbot – only a few months after the platform’s rapid rise in popularity.
December 4, 2025
Multiple NPM packages were compromised in late 2025 through account takeovers and malicious code injections.
December 4, 2025
A critical remote code execution vulnerability (CVE-2025-55182) has been found in React Server Components and in widely used frameworks such as Next.js.
October 24, 2025
On October 24, 2025, Microsoft published an out-of-band security update to a critical vulnerability in the Windows Server Update Service (WSUS).
August 8, 2025
A major security advisory was recently issued for Dell laptops, affecting millions of devices across more than 100 Latitude and Precision models.
July 21, 2025
CanSSOC became aware of a critical Remote Code Execution (RCE) vulnerability in Apache Tomcat, tracked as CVE-2025-24813.
July 3, 2025
The Stratascale Cyber Research Unit (CRU) team has identified two vulnerabilities in the Sudo utility. These vulnerabilities can result in the escalation of privileges to root on the impacted system.
May 1, 2025
The “AirBorne” vulnerability is a serious zero-click, remote code execution (RCE) exploit affecting Apple AirPlay-enabled devices.
March 20, 2025
CanSSOC became aware of a critical Remote Code Execution (RCE) vulnerability in Apache Tomcat, tracked as CVE-2025-24813.
March 6, 2025
A newly discovered critical vulnerability in Kibana, identified as CVE-2025-25012, exposes organizations to the risk of arbitrary code execution through prototype pollution.
March 6, 2025
Zero-day vulnerabilities in VMware products allow attackers with administrative privileges on a virtual machine to escape the VM sandbox and gain unauthorized access to the hypervisor, posing a significant risk to enterprise environments.
November 20, 2024
A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin ‘Really Simple Security’ (formerly ‘Really Simple SSL’), including both free and Pro versions.
October 28, 2024
On October 23rd, Fortinet published an advisory related to a critical FortiManager API vulnerability, tracked as CVE-2024-47575 (CVSSv3: 9.8). The vulnerability was exploited in zero-day attacks to steal sensitive files containing configurations, IP addresses, and credentials for managed devices.
October 16, 2024
Microsoft has released its October 2024 patch Tuesday updates, addressing 118 vulnerabilities including 5 zero-day vulnerabilities from which 2 are actively exploited.
September 27, 2024
On September 26th, a set of vulnerabilities in multiple components of the Common UNIX Printing System (CUPS) open-source printing system were discovered. These flaws could potentially allow a remote unauthenticated attacker to execute arbitrary commands on UNIX systems under certain conditions.
September 10, 2024
Veeam has issued security patches addressing 18 high and critical vulnerabilities across its Backup & Replication (VBR), Service Provider Console, and ONE products. The most severe flaw, CVE-2024-40711, is a remote code execution (RCE) vulnerability with a CVSS score of 9.8.
July 9, 2024
A critical unauthenticated remote code execution (RCE) vulnerability in OpenSSH, identified as CVE-2024-6387 and dubbed "regreSSHion" has been discovered, which allows attackers to gain root privileges on glibc-based Linux systems.
May 23, 2024
Veeam has notified one of our units about the vulnerabilities in their Backup Enterprise Manager product listed below. The worst of them, CVE-2024-29849, allows an attacker to log in to the web interface as any user.
March 8, 2024
On March 8, QNAP published a security bulletin disclosing three security flaws in its NAS software products. Exploitation of these vulnerabilities can lead to an authentication bypass, command injection and SQL injection.
