Skip to main content
University of Wisconsin–Madison
UW Crest
UW–⁠Madison Information Technology
Connecting & supporting our digital campus
  • Services
  • Learn
  • Community & governance Expand Collapse
    • Communities, committees, groups
    • IT Governance
  • IT projects & priorities Expand Collapse
    • IT project portfolio
    • IT Strategic Priorities 2022-2025
  • Cybersecurity Expand Collapse
    • Office of Cybersecurity
    • Data privacy week
  • Academic Technology
  • Accessibility Expand Collapse
    • Digital accessibility @ UW–‍Madison
    • Make It Accessible
    • Liaison Network
  • AI Expand Collapse
    • Generative AI services
    • Generative AI use & policies
    • CISO statement on use of generative AI
    • Microsoft Copilot
  • IT@UW–‍Madison Expand Collapse
    • About IT@UW–‍Madison
    • Division of Information Technology (DoIT)
    • Distributed IT
    • DoIT History
  • Accounts Expand Collapse
    • Email
    • MyUW
    • Learn@UW
    • Box
    • Google Apps
    • More Services
  • Zoom
  • Get help
  • Outages
  • Scam alerts
  1. Home
  2. Cybersecurity News
  3. Cybersecurity Announcements

Cybersecurity Announcements

Cybersecurity Announcement: Pre-authenticated RCE Vulnerability in Microsoft Windows SPNEGO Extended Negotiation Security Mechanism

Posted on December 20, 2022

Microsoft has recently revised the severity for SPNEGO Extended Negotiation security mechanism (NEGOEX) vulnerability to critical from its previous High severity from the September 2022 patch release. The vulnerability is being tracked as CVE-2022-37958.

Posted in Cybersecurity Announcements

Cybersecurity Announcement: WordPress Releases Patch for High Severity SQL Injection Vulnerability

Posted on September 1, 2022

WordPress has released version 6.0.2.  This security and maintenance release contains patches for 3 vulnerabilities, including a high severity SQL Injection vulnerability in the Links functionality (CVSS Score of 8.0), as well as two Medium Severity Cross-Site Scripting vulnerabilities.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Atlassian Bitbucket Server and Data Center Critical Vulnerability (CVE-2022-36804)

Posted on September 1, 2022

Atlassian has published a security advisory warning Bitbucket Server and Data Center users of a critical security flaw that allows remote attackers with access to public repositories or read access to private Bitbucket repositories to execute arbitrary code.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Microsoft Windows Support Diagnostic Tool and Point-to-Point Protocol Remote Code Execution Vulnerability (CVE-2022-34713) and (CVE-2022-30133)

Posted on August 10, 2022

Microsoft released announcements for known vulnerabilities addressed in their Tuesday Patch release. Two are considered Remote Code Execution vulnerabilities, meaning an attacker can exploit the system vulnerabilities remotely.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Django SQL injection vulnerability

Posted on July 5, 2022

Django, an open-source Python-based web framework, has detected a SQL injection vulnerability (CVE-2022-34265) in some recent versions.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Linux Local Privilege Escalation Vulnerability (CVE-2021-4034 PwnKit)

Posted on June 26, 2022

Qualys researchers discovered a Local Privilege Escalation vulnerability (CVE-2021-4034) in polkit’s pkexec, a program that is installed by default on every major Linux distribution.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Critical Illumina vulnerabilities (multiple CVEs)

Posted on June 7, 2022

Four critical vulnerabilities were discovered in Illumina Local Run Manager (LRM), software used by sequencing instruments to aid in genetic analysis.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Microsoft “Follina” zero-day in the wild (CVE-2022-30190)

Posted on June 1, 2022

About the Event A recently discovered zero-day vulnerability in all supported versions of Windows could allow an attacker to execute arbitrary code on affected machines. The flaw, dubbed “Follina”, exists due to improper validation of …

Posted in Cybersecurity Announcements, netid protected

Cybersecurity Announcement: Microsoft Remote Procedure Call Runtime Remote Code Execution Vulnerability

Posted on April 13, 2022

Microsoft released a patch as part of April 2022’s Patch Tuesday for a Remote Procedure Call Runtime Remote Code Execution Vulnerability (CVE-2022-26809). This vulnerability impacts most Windows Server and Desktop versions, including Windows 7 and Windows 11.

Posted in Cybersecurity Announcements, netid protected

Cybersecurity announcement: web fingerprint scanning Tue, Apr 5

Posted on April 5, 2022

Spring announced a remote code execution vulnerability in Spring Core, aka Spring4Shell. Details and actions here.

Posted in Cybersecurity Announcements, netid protected
  • You're on page 1
  • 2
  • Next page

Site footer content

University logo that links to main university website Part of the Universities of Wisconsin

IT @ UW-Madison

  • Services
  • Learn
  • Community & governance
  • IT project portfolio
  • IT Strategic Priorities 2022-2025
  • Cybersecurity
  • Digital accessibility
  • AI @ UW–‍Madison: use & policies

Quick Links

  • Get help
  • Get started with tech
  • Outages
  • Campus IT jobs
  • Website feedback, questions or accessibility requests
  • Accessibility@UW–‍Madison
  • Need an edit to a page in this site?

Contact Us

  • 1210 W Dayton St
    Madison, WI 53706
  • Email: webchanges@doit.wisc.edu
    • youtube
    • linkedin

Website feedback, questions or accessibility issues: webchanges@doit.wisc.edu | Learn more about accessibility at UW–Madison.

This site was built using the UW Theme | Privacy Notice | © 2025 Board of Regents of the University of Wisconsin System.