Skip to main content Skip to local navigation
Home » Articles posted by aalaily

aalaily

Microsoft 365 License Change for Offboarded Staff

Service Advisory Important Notice: Microsoft 365 Licence Change for Staff No Longer Employed at York University.  As part of York University’s ongoing commitment to responsible resource management, UIT will be downgrading the Microsoft 365 licensing for staff who are no longer employed at York University. Overview: All offboarded and inactive Staff accounts with A3 licences […]

Microsoft 365 License Change for Offboarded Staff

Service Advisory Important Notice: Microsoft 365 Licence Change for Staff No Longer Employed at York University.  As part of York University’s ongoing commitment to responsible resource management, UIT will be downgrading the Microsoft 365 licencing for staff who are no longer employed at York University. Overview: All offboarded and inactive Staff accounts with A3 licences […]

Apache HTTP Server Vulnerability (CVE-2026-23918)

    Information Security Advisory   Apache has released a security update to address a vulnerability (CVE‑2026‑23918) in Apache HTTP Server that may result in denial‑of‑service and potential remote code execution under specific configurations. Severity level: CVSS Score: 8.8/High. Description: CVE‑2026‑23918 is a double‑free vulnerability in the mod_http2 module of Apache HTTP Server that occurs […]

Linux Kernel Local Privilege Escalation (CVE-2026-31431)

    Information Security Advisory   A recently disclosed vulnerability (CVE‑2026‑31431), commonly referred to as “Copy Fail”, affects the Linux kernel and may allow a local, unprivileged attacker to escalate privileges and gain full root access on affected systems. Severity level: CVSS Score: 7.8/High. Description: CVE‑2026‑31431 is a local privilege escalation vulnerability caused by a […]

cPanel Authentication bypass Vulnerability (CVE-2026-41940)

    Information Security Advisory A critical security vulnerability (CVE-2026-41940) has been identified in cPanel, Web Host Manager (WHM) and WP Squared which may allow unauthenticated attackers to completely compromise affected systems through an authentication bypass in the login process. Severity level: CVSS Score: 9.8/Critical. Description: CVE‑2026‑41940 is a critical authentication bypass vulnerability in cPanel, […]

GitHub RCE Vulnerability (CVE-2026-3854)

    Information Security Advisory A recently disclosed vulnerability (CVE-2026-3854) affects GitHub.com and GitHub Enterprise Server and may allow unauthenticated attackers to achieve remote code execution (RCE)on GitHub Infrastructure. Severity level CVSS Score: 8.8/High Description: CVE‑2026‑3854 is a sever security vulnerability caused by improper sanitization of user‑supplied git push options within GitHub’s internal Git processing […]

ASP.NET Core Privilege Escalation Vulnerability (CVE-2026-40372)

    Information Security Advisory A recently disclosed vulnerability (CVE-2026-40372) affects a Windows-based application and may allow unauthenticated remote attackers to escalate privileges. Severity level CVSS Score: 9.1/Critical. Description: CVE‑2026‑40372 is a critical security vulnerability that arises from improper control of file names or file paths within a Windows-based application. The affected component processes user-supplied […]

Adobe Acrobat security vulnerability (CVE-2026-34621)

    Information Security Advisory A recently disclosed high‑severity vulnerability in Adobe Acrobat and Acrobat Reader (CVE‑2026‑34621) allows attackers to execute arbitrary code on affected systems by tricking users into opening a specially crafted PDF file. Severity level: CVSS Score: 8.6/High Description: Adobe Acrobat and Acrobat Reader contain an improperly controlled modification of object prototype […]

Ninja Forms WordPress Plugin Vulnerability (CVE-2026-0740)

    Information Security Advisory A recently disclosed critical vulnerability in the Ninja Forms – File Uploads plugin for WordPress (CVE‑2026‑0740) allows unauthenticated remote attackers to upload arbitrary files, potentially leading to remote code execution and full site compromise. Severity level: CVSS Score: 9.8/Critical Description: The Ninja Forms – File Uploads plugin for WordPress fails […]

Ninja Forms WordPress Plugin Vulnerability (CVE-2026-0740)

    Information Security Advisory A recently disclosed critical vulnerability in the Ninja Forms – File Uploads plugin for WordPress (CVE‑2026‑0740) allows unauthenticated remote attackers to upload arbitrary files, potentially leading to remote code execution and full site compromise. Severity level: CVSS Score: 9.8/Critical Description: The Ninja Forms – File Uploads plugin for WordPress fails […]