Loughborough University has disclosed a critical vulnerability in its legacy student portal system exposing sensitive PII and academic data. The flaw, tracked under internal reference LU-2024-001, affects all versions prior to the recent patch and may have been exploited in limited attacks. Immediate patching is required to prevent unauthorized access to student records, financial data, and internal communications.