Sharepoint Security
The latest Sharepoint Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches SharePoint XSS Vulnerability CVE-2026-55034: What You Need to Patch Now
Microsoft released its July 2026 security updates on July 14, and among the patches is a fix for CVE-2026-55034—an Important-rated cross-site scripting (XSS) flaw in on-premises SharePoint Server....
Microsoft’s Latest SharePoint Patch Fixes a Tricky XSS—And Packs Critical Fixes You Can’t Ignore
Microsoft’s July 14, 2026 security updates for SharePoint Server close an authenticated cross-site scripting hole that, on its own, scores a medium 4.6 on the CVSS scale. The flaw, tracked as...
Microsoft Fixes Office and SharePoint Bug That Could Expose Sensitive Data — Patch Now
Microsoft released security updates on July 14, 2026, that fix a memory disclosure vulnerability in Microsoft Office and on-premises SharePoint Server. Tracked as CVE-2026-55023, the flaw can be...
Microsoft’s July 2026 SharePoint Update Blocks Spoofing Attacks That Exploit Low-Privilege Accounts
Microsoft’s July 2026 security updates, released on Patch Tuesday, deliver a critical fix for a SharePoint Server vulnerability that lets attackers with any authenticated account inject malicious...
July SharePoint Patches Close Spoofing Hole: Here’s Why You Can’t Skip the Workflow Manager Update First
Microsoft fixed a spoofing vulnerability in its on-premises SharePoint servers on July 14, 2026. The patch lands for SharePoint Server 2016, 2019, and Subscription Edition under CVE-2026-55020. But...
Microsoft Patches SharePoint XSS Spoofing Flaw in July 2026 Update – Here’s How to Secure Your Farm
Microsoft released fixes on July 14, 2026, for a cross-site scripting (XSS) vulnerability in on-premises SharePoint Server that could let an authenticated attacker place deceptive content on pages...
Microsoft’s Critical SharePoint Flaw Is a Network-Based Code Execution Nightmare—Update Your Servers Now
Microsoft has disclosed a critical vulnerability in on-premises SharePoint Server that lets a remote attacker execute arbitrary code without needing a single credential or any user interaction....
Patch Now: CISA Adds Two Microsoft Zero-Days and Two SonicWall Flaws to Must-Fix List
The Cybersecurity and Infrastructure Security Agency added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on July 14, 2026. Two of them — flaws in Microsoft...
Microsoft's 570-Fix Patch Tuesday: Two Zero-Days Exploited, BitLocker Bypass Disclosed
On July 14, Microsoft unloaded a record-breaking 570 security fixes across its product portfolio — the largest Patch Tuesday in the company’s history. Two of the vulnerabilities are zero-days...
Prepare Now: Microsoft Permanently Removes Kerberos RC4 Rollback on July 14
Microsoft’s July 14, 2026 cumulative updates will strip out the long‑standing Kerberos RC4 rollback control from all supported Windows Server domain controllers. At the same time, administrators...
How a 50-Person Firm Tamed Microsoft 365 Copilot with Governance and a SharePoint Rebuild
A newly published Microsoft customer story reveals how Struber, a small Australian infrastructure consultancy, successfully deployed Microsoft 365 Copilot across its 50-person workforce by...
Patch Now: Critical SharePoint XSS Spoofing Fix CVE-2026-45464
Microsoft has addressed a notable security vulnerability in SharePoint Server, releasing a fix for CVE-2026-45464 on June 9, 2026. Rated as Important, this cross-site scripting (XSS) spoofing flaw...