Reporting a security vulnerability

This form is only for reporting technical security vulnerabilities in University systems or services (eg. a flaw that could allow unauthorised access or expose data). To report phishing, a cybersecurity incident, or a privacy incident, visit the Cybersecurity reporting page.

The University of Melbourne is committed to protecting the privacy, security and availability of its systems and services – and we value the contributions of security researchers in helping us reduce cyber risk.

If you’ve discovered a potential vulnerability that could affect the confidentiality, integrity or availability of University information, systems or services, please report it using the form below.

We’ll review and respond to every submission, investigate thoroughly, and take appropriate steps to resolve the issue.

Please avoid the following activities

  • Social engineering or phishing
  • Denial of service (DoS or DDoS) attacks
  • Physical security testing
  • Changing, accessing, or deleting data

You don’t need to report the following activities

These issues are already managed through internal processes.

  • Expired or self-signed certificates
  • Insecure SSL protocols
  • Open ports
  • Clickjacking