Instructure Canvas security incident

Incident Report for FeedbackFruits

Resolved

There are no known issues with FeedbackFruits integrations in Canvas. Some institutions have chosen to isolate FeedbackFruits from their Canvas instances at this time, or have made their Canvas instances temporarily unavailable entirely.

For overal guidance on the current Instructure incident, see: https://help.feedbackfruits.com/hc/en-us/articles/35419159592338-Canvas-security-incident-May-7th-2026-update-option-to-isolate-your-integration
Posted May 08, 2026 - 14:54 UTC

Monitoring

All FeedbackFruits integrations that depended on https://canvas.instructure.com/ being available, have now been restored.

There are no known issues with FeedbackFruits integrations in Canvas. Some institutions have chosen to isolate FeedbackFruits from their Canvas instances at this time, or have made their Canvas instances temporarily unavailable entirely.

For overal guidance on the current Instructure incident, see: https://help.feedbackfruits.com/hc/en-us/articles/35419159592338-Canvas-security-incident-May-7th-2026-update-option-to-isolate-your-integration
Posted May 08, 2026 - 10:40 UTC

Update

Instructure has taken https://canvas.instructure.com/ offline, as it relates to the Free-For-Teacher attack vector that is being referred to on https://www.instructure.com/incident_update.

As https://canvas.instructure.com/ is part of the LTI launch for some integration configurations in Canvas (unrelated to the Free-For-Teacher program), this can result in "Important Update: Free-for-Teacher Access Temporarily Disabled" being shown instead of FeedbackFruits tools launching.

We have reached out to Instructure for guidance on this. Institutions affected by this, who want to keep their FeedbackFruits integration active at this stage of the Instructure incident, are advised to reach out to support@feedbackfruits.com to ease communication.

For overal guidance on the current Instructure incident, see: https://help.feedbackfruits.com/hc/en-us/articles/35419159592338-Canvas-security-incident-May-7th-2026-update-option-to-isolate-your-integration
Posted May 08, 2026 - 09:40 UTC

Identified

Instructure has now provided additional information on their incident: https://www.instructure.com/incident_update

We have emailed FeedbackFruits partner institutions with additional guidance, see https://help.feedbackfruits.com/hc/en-us/articles/35419159592338-Canvas-security-incident-May-7th-2026-update-option-to-isolate-your-integration
Posted May 08, 2026 - 08:43 UTC

Update

Instructure has placed https://canvas.instructure.com/ in maintenance mode, which blocks launching FeedbackFruits in some configurations, showing an "Canvas is currently undergoing maintenance" notice.

We expect to have additional guidance shared on the wider incident within the next 30min.
Posted May 08, 2026 - 07:40 UTC

Investigating

We are working on guidance for institutions that use Instructure (cloud based) Canvas instances, after a new security incident (https://status.instructure.com/incidents/m88d7ymwpzpy) was reported in the last 24h. At the moment, FeedbackFruits integrations with Canvas instances are not disabled proactively. We expect to have guidance shared within the next 2 hours.
Posted May 08, 2026 - 06:12 UTC
This incident affected: Integrations (Canvas).