Modern Work Weekly — Week of 2026-07-14
A light data week dominated by MSRC vulnerability disclosures for gawk and node-tar, plus an OWA Light retirement announcement that Exchange Server admins need to plan for.
Top 5 This Week
OWA Light retirement in Exchange Server — Microsoft has announced plans to disable OWA Light in a future Exchange Server update. If any users or helpdesk workflows still rely on the light client, start migration planning now before the update lands.
Three gawk buffer overflow CVEs (CVE-2026-40468, CVE-2026-40469, CVE-2026-40553) — Heap and stack buffer overflows published for gawk. Review whether gawk is present in any managed Linux endpoints or server workloads and track patch availability.
node-tar DoS vulnerabilities (CVE-2026-59873, CVE-2026-59871) — Two CVEs covering decompression/parse DoS and process crash via PAX path type confusion in node-tar. Any build pipelines, automation agents, or services using node-tar need patching.
Chromium CVE-2026-14428 insufficient input validation in Dawn — Edge (Chromium-based) inherits this GPU/graphics pipeline vulnerability. Ensure Edge is on the latest stable release across your managed fleet.
CVE-2026-15308 HTMLParser CPU-exhaustion DoS — Repeated unterminated markup declarations can exhaust CPU. Relevant for any Python-based backend services or automation tooling parsing untrusted HTML.
Apps
Upcoming retirement of OWA Light in Exchange Server [GA] — Microsoft will retire and disable OWA Light in a future Exchange Server cumulative update; no specific date is given yet, but the direction is firm. Audit your organization for any users, browser policies, or helpdesk documentation pointing to the
?layout=lightURL parameter or the light client bookmark, and redirect them to standard Outlook on the web. Update internal training materials and review whether any accessibility accommodations were served by OWA Light that now need an alternative path.Solutions for document-centric business processes - Portal Systems - SharePoint Partner Spotlight [GA] — Portal Systems AG showcases ECM solutions built on SPFx for SharePoint and Microsoft 365. Worth reviewing if your organization is evaluating document-centric workflow tooling on top of SharePoint rather than a third-party ECM platform.
Proven intranet framework - Involv Intranet - SharePoint Partner Spotlight [GA] — Involv Intranet provides a branded, mobile-ready intranet built on SPFx with 50-plus configurable components. If your organization has an intranet refresh on the roadmap, this is a reference point for what the SPFx partner ecosystem can deliver out of the box.
Streamlining business processes with Microsoft 365 - ShareCloud - SharePoint Partner Spotlight [GA] — ShareCloud demonstrates productized SharePoint-based business application solutions built on Microsoft 365 and Power Platform. Relevant context if you are evaluating partners to extend SharePoint into line-of-business workflows without custom development overhead.
Visibility & Automation
CVE-2026-40468 Heap buffer overflow in gawk [GA] — Heap buffer overflow in gawk published by MSRC this week. Inventory managed Linux endpoints and any Windows Subsystem for Linux environments where gawk may be installed, and apply vendor patches when available.
CVE-2026-40469 Heap buffer overflow in gawk [GA] — A second heap buffer overflow CVE in gawk, tracked separately from CVE-2026-40468. Treat both together when assessing exposure; patch the same gawk installations identified for the previous CVE.
CVE-2026-40553 Stack-based buffer overflow in gawk [GA] — Stack-based buffer overflow in gawk completes a trio of gawk CVEs this week. Stack overflows carry elevated exploitation risk relative to heap variants; prioritize remediation accordingly.
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input [GA] — Unlimited input during decompression or parsing in node-tar can cause a denial of service. Identify any CI/CD pipelines, automation agents, or Node.js services consuming node-tar and validate they are running a patched version.
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion [GA] — Type confusion in PAX numeric path handling causes a process crash in node-tar. This pairs with CVE-2026-59873; remediate both in the same pass when updating node-tar dependencies.
CVE-2026-15308 Incremental HTMLParser feed() CPU-exhaustion DoS [GA] — Repeated unterminated markup declarations passed to the incremental HTMLParser feed() method can exhaust CPU. Review Python-based services, automation scripts, or backend tools that parse untrusted HTML and update the affected library once a patch is released.
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn [GA] — Insufficient input validation in Chromium’s Dawn graphics layer affects Microsoft Edge. Confirm your Edge deployment is on the current stable channel build; if you manage Edge updates via Intune or a software update policy, validate compliance reports show no outdated versions.
Action Required
Upcoming retirement of OWA Light in Exchange Server [GA] — Plan within 30 days: No specific retirement date is published yet, but Microsoft has confirmed this feature will be disabled in an upcoming Exchange Server update. Identify users relying on OWA Light, update helpdesk documentation, remove or redirect any internal bookmarks to the light client URL, and confirm that any accessibility accommodations previously handled by OWA Light have a supported replacement in modern Outlook on the web.
CVE-2026-40553 Stack-based buffer overflow in gawk [GA] — Patch when available: Stack-based overflow in gawk is the highest-risk of the three gawk CVEs this week. Inventory gawk across managed Linux endpoints, WSL environments, and any server workloads, and prioritize patching once the upstream fix is available in your distribution’s package repository.
CVE-2026-59871 and CVE-2026-59873 node-tar vulnerabilities [GA] — Audit and patch within 30 days: Both node-tar CVEs affect process stability and availability. Scan your Node.js dependency trees across CI/CD pipelines and deployed services for node-tar versions below the patched release, and update as part of your next dependency maintenance window.
Sources
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40468
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40469
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40553
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59873
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59871
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15308
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-14428
- https://www.youtube.com/shorts/0heeppCYrmM
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/solutions-for-document-centric-business-processes-portal-systems/ba-p/4515217
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/proven-intranet-framework-involv-intranet-sharepoint-partner/ba-p/4519241
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/streamlining-business-processes-with-microsoft-365-sharecloud/ba-p/4533560
- https://techcommunity.microsoft.com/t5/exchange-team-blog/upcoming-retirement-of-owa-light-in-exchange-server/ba-p/4534943
- https://www.youtube.com/shorts/YImum6f4Z2w
