Skip to main content Skip to local navigation

Alerts

Protecting University-Owned Devices

Dear colleagues, As cyber threats targeting higher education continue to increase, York University is taking steps to strengthen the security standards applied to all University-owned computers. Effective June 22, 2026, all University-owned computers must meet a defined Security Baseline that specifies the minimum set of protections to safeguard University systems, research, and data. This baseline […]

VMware vCenter Server multiple vulnerabilities (CVE-2026-59309,CVE-2026-59310)

    Information Security Advisory A recently disclosed set of vulnerabilities (CVE-2026-59309 and CVE-2026-59310) affects VMware vCenter Server and may allow a remote attacker with network access to bypass authentication and execute arbitrary code on vulnerable systems. Severity level: CVSS Score: 9.8/Critical. Description: CVE-2026-59309 is a critical authentication bypass vulnerability in the VMware Directory Service […]

Service Advisory - Unified Print Management - Wednesday July 29, 2026 7:30 AM - 8:00 AM

    Service Advisory Please share the following with your teams. Service Maintenance: Unified Print Management Scheduled Maintenance Window: Start: Wednesday July 29, 2026 7:30 AM End: Wednesday July 29, 2026 8:00 AM Impact/Details: Print services in the Administrative offices, Faculty student labs, and Libraries will not be available for a brief 5 minutes when we restart the service. UIT teams […]

Service Advisory - Central SCCM - Wednesday July 29, 2026 8:00 a.m. - Thursday July 30, 2026 5:00 p.m. [REMINDER]

    Service Advisory Please share the following with your teams. Service Maintenance: Central SCCM Maintenance window: Start Date/Time: Wednesday July 29, 2026 8:00 a.m. End Date/Time: Thursday July 30, 2026 5:00 p.m. Impact/Details: UIT teams will complete necessary server OS and database upgrades. Central SCCM will not be available to deploy Windows OS and application packages […]

WordPress RCE Vulnerability (CVE-2026-63030)

    Information Security Advisory A recently discovered vulnerability (CVE-2026-63030) that affects WordPress Core and allow an unauthenticated remote attacker to achieve remote code execution (RCE). Severity level: CVSS Score: 9.8/Critical. Description: WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing […]

Service Advisory - York Phish Alert - Tuesday July 21, 11:00 AM - 12:00 PM

    Service Advisory Please share the following with your teams. Service Maintenance: The Information Security team will be replacing the Cofense Phishing Reporter add-on in the Google tenant with our new solution, York Phish Alert. York Phish Alert is an internally developed Gmail add-on that provides the same functionality as Cofense while allowing us […]

Service Advisory - York Phish Alert - Tuesday July 21, 11:00 AM - 12:00 PM

    Service Advisory Please share the following with your teams. Service Maintenance: The Information Security team will be replacing the Cofense Phishing Reporter add-on in the Google tenant with our new solution, York Phish Alert. York Phish Alert is an internally developed Gmail add-on that provides the same functionality as Cofense while allowing us […]

Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412)

    Information Security Advisory A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access. Severity level: CVSS Score: 9.8/Critical. Description: CVE-2026-53412 is a critical vulnerability caused by improper input validation […]

Linux kernel vulnerability (CVE-2026-43503)

    Information Security Advisory A recently disclosed vulnerability (CVE-2026-43503), also known as DirtyClone, affects the Linux kernel and may allow a local unprivileged user to gain root privileges on vulnerable systems. Severity level: CVSS Score: 8.8/High. Description: CVE-2026-43503 (DirtyClone) is a high-severity Linux kernel privilege escalation vulnerability caused by improper handling of shared memory […]

Service Advisory - Unified Print Management - Thursday July 2, 2026 10:00 p.m. - 10:15 p.m.

    Service Advisory Please share the following with your teams. Service Maintenance: Unified Print Management Scheduled Maintenance Window: Start: Thursday July 2, 2026 10:00 p.m. End: Thursday July 2, 2026 10:15 p.m Impact/Details: Print services in the Administrative offices, Faculty student labs, and Libraries will not be available. UIT teams will implement changes needed to improve service reliability and security […]