Sharepoint Security
The latest Sharepoint Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-45454: SharePoint RCE Flaw Puts On-Prem Servers at Risk—Patch Now
Microsoft’s June 2026 security update bundle dropped a critical patch that every SharePoint administrator needs to apply immediately. Tucked inside the Security Update Guide under CVE-2026-45454 is...
CVE-2026-45468 SharePoint XSS Spoofing: What Server 2016 & 2019 Admins Must Know
Microsoft's June 9, 2026 Patch Tuesday brought an important fix for on-premises SharePoint farms: CVE-2026-45468, an Important-rated cross-site scripting (XSS) spoofing vulnerability. The flaw...
Microsoft's April 2026 Patch Tuesday Addresses 165 Vulnerabilities Including SharePoint Zero-Days and AI Risks
Microsoft's April 2026 security update cycle addresses 165 vulnerabilities across its product ecosystem, marking one of the largest Patch Tuesday releases in recent memory. The sheer volume of fixes...
Microsoft Patches Critical SharePoint RCE Vulnerability CVE-2026-26106 in March 2026 Security Update
Microsoft released security updates on March 10, 2026 addressing a high-risk remote code execution vulnerability in on-premises SharePoint Server tracked as CVE-2026-26106. This critical flaw allows...
Microsoft Patches Critical SharePoint RCE Vulnerability CVE-2026-26114 in March 2026 Security Update
Microsoft released a critical security update on March 10, 2026 addressing a high-severity remote code execution vulnerability in on-premises Microsoft SharePoint Server. Tracked as CVE-2026-26114,...
Critical SharePoint RCE Patched — Here’s Why You Must Rotate MachineKeys
On January 13, 2026, Microsoft shipped a cumulative update for SharePoint Server that stomps out a dangerous remote code execution flaw tagged CVE-2026-20947. The vulnerability, rated critical by...
CVE-2026-20947 Patch Alert: Your SharePoint Servers May Be Under Immediate Threat
Microsoft has published a security advisory for a remote code execution vulnerability in SharePoint Server, tracked as CVE-2026-20947, but is withholding the technical details that would normally let...
Microsoft Flags Critical SharePoint Server RCE — On-Premises Admins Must Patch and Hunt Immediately
Microsoft on Thursday confirmed a remote code execution vulnerability in SharePoint Server that can give attackers full control over unpatched on-premises farms, and the company is treating it as an...
SharePoint Servers at Risk: Patch Now for CVE-2026-20963 to Block RCE Attacks
Microsoft has published a new critical remote code execution vulnerability—CVE-2026-20963—affecting on-premises SharePoint Server, with the vendor urging immediate patching and cryptographic key...
CVE-2026-20951: Critical SharePoint RCE Vulnerability - Patch & Hunt Guide
Microsoft has issued an urgent security advisory for CVE-2026-20951, a critical remote code execution vulnerability affecting Microsoft SharePoint Server that requires immediate attention from...
CVE-2025-64672: Critical SharePoint Spoofing Vulnerability Demands Immediate Patching
Microsoft has issued an urgent security advisory for CVE-2025-64672, a high-severity spoofing vulnerability affecting on-premises SharePoint Server deployments that could allow attackers to...
Microsoft Releases Patch for High-Severity SharePoint RCE — Urgent Action Required for On-Premises Farms
A dangerous vulnerability in SharePoint Server lets attackers seize full control of on-premises farms, and Microsoft has just released the fix. The flaw, tracked as CVE-2025-62204, enables remote...