This is a notice from the Information Security Office to alert you to a critical vulnerability that impacts WordPress, a common website management platform[1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.
Security Alerts
July 20, 2026
May 8, 2026
To the UCB-Security community,
This is a notice from the Information Security Office to alert you to critical vulnerabilities that impact Linux systems. Please share this alert internally with IT admins and service owners who run Linux so they are prepared to take action when patches become available.
This is a preliminary announcement. More information will follow when we have it.
May 6, 2026
SUMMARY
A critical double-free vulnerability in Apache HTTP Server's HTTP/2 module is vulnerable to unauthenticated Remote Code Execution (RCE) and Denial of Service (DoS) attacks. [1]
IMPACT
Attackers can potentially execute arbitrary code remotely by exploiting this vulnerability or conduct Denial of Service attacks by continually crashing Apache worker processes. .
March 18, 2026
January 30, 2026
To the UCB-Security community,
This is a notice from the Information Security Office to alert you to a critical vulnerability that impacts WordPress servers using the Modular DS plugin. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.
To the UCB-Security community,
This is a notice from the Information Security Office to alert you to a high severity vulnerability that impacts MongoDB Server [1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.
December 5, 2025
April 24, 2025
May 7, 2024
April 29, 2024
January 9, 2023
March 31, 2022
December 10, 2021
September 14, 2021
July 27, 2021
April 5, 2021
Updated May 11, 2021:
UCOP Notice to UC Community: https://ucnet.universityofcalifornia.edu/data-security/index.html
Updated Apr. 15, 2021:
March 31, 2021
Mar. 31st - The Internal Revenue Service issued a warning of an ongoing IRS-impersonation scam that appears to primarily target educational institutions, including students and staff who have ".edu" email addresses. The phishing emails appear to target university and college students from both public and private, profit and non-profit institutions.
The fraudulent email displays the IRS logo and uses various subject lines such as "Tax Refund Payment" or "Recalculation of your tax refund payment." It asks people to click a link and submit a form to claim their refund.
February 11, 2021
January 26, 2021
- 1 of 2 Security Alerts (Current page)
- 2 of 2 Security Alerts
- next › Security Alerts
- last » Security Alerts