The Instructure Canvas Breach (2026): How XSS in a Support Ticket Compromised 275 Million Students (opens in new tab)
A single support ticket became the front door to 275 million student records. The Canvas breach shows how quickly untrusted user content can become a serious security incident when it is rendered inside privileged internal tooling. This was not an exotic attack chain; it was stored XSS, over-scoped access,
Read the original article