News | UIT /uit Wed, 29 Jul 2026 19:51:23 +0000 en-CA hourly 1 https://wordpress.org/?v=6.9.5 VMware vCenter Server multiple vulnerabilities (CVE-2026-59309,CVE-2026-59310) /uit/2026/07/vmware-vcenter-server-multiple-vulnerabilities-cve-2026-59309cve-2026-59310/ Wed, 29 Jul 2026 19:42:38 +0000 /uit/?p=40392

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently disclosed set of vulnerabilities (CVE-2026-59309 and CVE-2026-59310) affects VMware vCenter Server and may allow a remote attacker with network access to bypass authentication and execute arbitrary code on vulnerable systems.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE-2026-59309 is a critical authentication bypass vulnerability in the VMware Directory Service component of VMware vCenter Server. A remote attacker with network access to vCenter can exploit this flaw to bypass authentication controls and gain unauthorized access to the affected system.
CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog Server component. A remote attacker can leverage this flaw to access unauthorized files and potentially achieve arbitrary code execution on the vCenter Server.

Affected Versions:

  • VMware vCenter Server 8.0
  • VMware Cloud Foundation ( 9.0.x, 9.1.x)
  • VMware vSphere Foundation (9.0.x, 9.1.x)
  • VMware Telco Cloud Platform (3.0,4.x,5.0.x,5.1.x)
  • VMware Telco Cloud Infrastructure 3.0


Impact:

Successful exploitation may allow attackers to bypass authentication or execute arbitrary code on the affected server.

Resolution:
Upgrade to the following fixed versions or later:-

  • VMware Cloud Foundation/ VMware vSphere Foundation 9.1.0.0300.
  • VMware Cloud Foundation/ VMware vSphere Foundation 9.0.2.0100
  • VMware vCenter 8.0 U3k.


Reference:

 

UIT Information Security



Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Service Advisory - Unified Print Management - Wednesday July 29, 2026 7:30 AM - 8:00 AM /uit/2026/07/service-advisory-unified-print-management-wednesday-july-29-2026-730-am-800-am/ Tue, 28 Jul 2026 15:06:14 +0000 /uit/?p=40390

 

A picture containing text  Description automatically generated

 

Service Advisory


Please share the following with your teams.

Service Maintenance:
Unified Print Management

Scheduled Maintenance Window:
Start:
 Wednesday July 29, 2026 7:30 AM
End: Wednesday July 29, 2026 8:00 AM

Impact/Details:

  • Print services in the Administrative offices, Faculty student labs, and Libraries will not be available for a brief 5 minutes when we restart the service.
  • UIT teams will implement necessary security changes to improve compliance.

  

We thank you for your time and continued understanding.

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Service Advisory - Central SCCM - Wednesday July 29, 2026 8:00 a.m. - Thursday July 30, 2026 5:00 p.m. [REMINDER] /uit/2026/07/service-advisory-central-sccm-wednesday-july-29-2026-800-a-m-thursday-july-30-2026-500-p-m-reminder/ Tue, 28 Jul 2026 13:51:04 +0000 /uit/?p=40386

 

A picture containing text  Description automatically generated

 

Service Advisory


Please share the following with your teams.


Service Maintenance:
Central SCCM

Maintenance window:
Start Date/Time:
 Wednesday July 29, 2026 8:00 a.m.
End Date/Time: Thursday July 30, 2026 5:00 p.m.

Impact/Details:

  • UIT teams will complete necessary server OS and database upgrades.
  • Central SCCM will not be available to deploy Windows OS and application packages during the maintenance window.
  • IT teams should not schedule deployment tasks during the maintenance window.


We thank you for your time and continued understanding.

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
WordPress RCE Vulnerability (CVE-2026-63030) /uit/2026/07/wordpress-rce-vulnerability-cve-2026-63030/ Tue, 21 Jul 2026 15:58:41 +0000 /uit/?p=40354

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently discovered vulnerability (CVE-2026-63030) that affects WordPress Core and allow an unauthenticated remote attacker to achieve remote code execution (RCE).

Severity level:
CVSS Score: 9.8/Critical.

Description:

WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. CVE-2026-63030 is a critical REST API batch endpoint route confusion vulnerability in WordPress Core. The flaw causes a mismatch between request validation and execution within the WordPress REST API batch processing mechanism, allowing specially crafted requests to bypass expected security controls. When chained with CVE-2026-60137, an SQL injection vulnerability in WP_Query, an unauthenticated attacker can achieve remote code execution and fully compromise a vulnerable WordPress site.

Affected Versions:

  • WordPress 6.9.0 through 6.9.4
  • WordPress 7.0 through 7.0.1
  • WordPress 7.1 beta releases prior to 7.1 beta 2


Impact:

Successful exploitation may allow attackers to execute arbitrary code on the affected server.

Resolution:
Upgrade affected WordPress installations to:-

  • WordPress 6.9.5 or later.
  • WordPress 7.0.2 or later.
  • WordPress 7.1 beta 2 or later.

 


Reference:

 

UIT Information Security



Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Service Advisory - 91亚色 Phish Alert - Tuesday July 21, 11:00 AM - 12:00 PM /uit/2026/07/service-advisory-york-phish-alert-tuesday-july-21-1100-am-1200-pm/ Tue, 21 Jul 2026 15:41:55 +0000 /uit/?p=40350

 

A picture containing text  Description automatically generated

 

Service Advisory


Please share the following with your teams.

Service Maintenance:
The Information Security team will be replacing the Cofense Phishing Reporter add-on in the Google tenant with our new solution, 91亚色 Phish Alert. 91亚色 Phish Alert is an internally developed Gmail add-on that provides the same functionality as Cofense while allowing us to gain full control over our reporting pipeline and improve our phishing investigation capabilities.

Outage window:
Start:
Tuesday, July 21, 2026, 11:00 AM
End: 
Tuesday, July 21, 2026, 12:00 PM

Impact/Details:

  • No service impact expected during the change window; the deployment of the add-on can be introduced without interrupting access to email / other University systems and services

We thank you for your time and continued understanding.

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Service Advisory - 91亚色 Phish Alert - Tuesday July 21, 11:00 AM - 12:00 PM /uit/2026/07/service-advisory-york-phish-alert-tuesday-july-21-1100-am-1200-pm-2/ Tue, 21 Jul 2026 15:41:55 +0000 /uit/?p=40352

 

A picture containing text  Description automatically generated

 

Service Advisory


Please share the following with your teams.

Service Maintenance:
The Information Security team will be replacing the Cofense Phishing Reporter add-on in the Google tenant with our new solution, 91亚色 Phish Alert. 91亚色 Phish Alert is an internally developed Gmail add-on that provides the same functionality as Cofense while allowing us to gain full control over our reporting pipeline and improve our phishing investigation capabilities.

Outage window:
Start:
Tuesday, July 21, 2026, 11:00 AM
End: 
Tuesday, July 21, 2026, 12:00 PM

Impact/Details:

  • No service impact expected during the change window; the deployment of the add-on can be introduced without interrupting access to email / other University systems and services

We thank you for your time and continued understanding.

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412) /uit/2026/07/zoom-workplace-for-windows-improper-input-validation-cve-2026-53412/ Thu, 16 Jul 2026 17:08:25 +0000 /uit/?p=40348

 

A picture containing text  Description automatically generated

 


Information Security Advisory


A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE-2026-53412 is a critical vulnerability caused by improper input validation in Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows. An unauthenticated attacker can exploit the flaw remotely over a network to perform an account takeover.

Affected Versions:
Zoom Workplace for Windows before 7.0.0.
Zoom Workspace VDI client for Windows before (7.0.10, 6.6.15, 6.5.18)

Impact:

Successful exploitation may allow attackers to take over affected Zoom account.

Resolution:
Upgrade affected software to the latest supported versions.

Reference:

 




UIT Information Security

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Linux kernel vulnerability (CVE-2026-43503) /uit/2026/07/linux-kernel-vulnerability-cve-2026-43503/ Tue, 14 Jul 2026 17:01:54 +0000 /uit/?p=40334

 

A picture containing text  Description automatically generated

 


Information Security Advisory


A recently disclosed vulnerability (CVE-2026-43503), also known as DirtyClone, affects the Linux kernel and may allow a local unprivileged user to gain root privileges on vulnerable systems.

Severity level:
CVSS Score: 8.8/High.

Description:

CVE-2026-43503 (DirtyClone) is a high-severity Linux kernel privilege escalation vulnerability caused by improper handling of shared memory fragments in the networking subsystem. A local attacker can exploit the flaw to modify file-backed page-cache memory and alter the behavior of privileged executables, potentially gaining root privileges on the affected system. The attack occurs in memory without modifying files on disk, making detection more difficult.

Affected Versions:
Major Linux distributions.
Linux systems running kernel versions prior to vendor-provided fixes for CVE-2026-43503.

Impact:

Successful exploitation may allow attackers to escalate privileges from local user account to root.

Resolution:
Apply the latest security updates provided by the Linux distribution and upgrade the kernel.

Reference:

 


UIT Information Security

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>
Enrol your Mac in Modern Device Management (JAMF) /uit/2026/07/enrol-mac/ Wed, 08 Jul 2026 18:57:48 +0000 /uit/?p=40290 ]]> Service Advisory - Unified Print Management - Thursday July 2, 2026 10:00 p.m. - 10:15 p.m. /uit/2026/06/service-advisory-unified-print-management-thursday-july-2-2026-1000-p-m-1015-p-m/ Fri, 26 Jun 2026 16:13:46 +0000 /uit/?p=40273

 

A picture containing text  Description automatically generated

 

Service Advisory


Please share the following with your teams.


Service Maintenance:
Unified Print Management

Scheduled Maintenance Window:
Start:
 Thursday July 2, 2026 10:00 p.m.
End: Thursday July 2, 2026 10:15 p.m

Impact/Details:

  • Print services in the Administrative offices, Faculty student labs, and Libraries will not be available.
  • UIT teams will implement changes needed to improve service reliability and security compliance.

 

 



We thank you for your time and continued understanding.

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

 | VISIT WWW.YORKU.CA
This email was sent by: 91亚色, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

]]>