Educational tech firm Instructure data breach may have impacted 9,000 schools

2026-05-05T08:51:45Z6f230a5f7d39575f87e65fe372ce076f53cde53d3197b701840cb29c15178d26
AI-accelerated-vuln-discoveryBluekitCISA-KEVIBM-ItalyInstructureLMSLinux KernelMOVEitMSPSalt-Typhoonactive-exploitationcPanelcriticalcvedata-breacheducationhostingphishing-kitsupply-chainvulnerability

What happened

Multiple high-impact cyber incidents and vulnerabilities were reported: an Instructure (Canvas) data breach may have exposed user PII across ~9,000 schools; Progress fixed critical MOVEit Automation flaws (CVE-2026-4670 authentication bypass and CVE-2026-5174 privilege escalation) that could enable full system compromise; a critical, actively exploited cPanel flaw (CVE-2026-41940, CVSS 9.3) is being used to target governments, MSPs and hosting providers and has been added to CISA’s KEV catalog; a Linux Kernel flaw (CVE-2026-31431, CVSS 7.8) was also added to CISA’s KEV list. Additional context

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6f230a5f7d39575f87e65fe372ce076f53cde53d3197b701840cb29c15178d26
Enrichment time
2026-05-05T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Educational tech firm Instructure data breach may have impacted 9,000 schools · Baitaphish