Modern Work Weekly - Week of 2026-07-14
A light data week dominated by MSRC vulnerability disclosures for gawk and node-tar, plus an OWA Light retirement announcement that Exchange Server admins need to plan for.
Top 5
OWA Light retirement in Exchange Server — Microsoft has announced plans to disable OWA Light in a future Exchange Server update. If any users or helpdesk workflows still rely on the light client, start migration planning now before the update lands.
Three gawk buffer overflow CVEs (CVE-2026-40468, CVE-2026-40469, CVE-2026-40553) — Heap and stack buffer overflows published for gawk. Review whether gawk is present in any managed Linux endpoints or server workloads and track patch availability.
node-tar DoS vulnerabilities (CVE-2026-59873, CVE-2026-59871) — Two CVEs covering decompression/parse DoS and process crash via PAX path type confusion in node-tar. Any build pipelines, automation agents, or services using node-tar need patching.
Chromium CVE-2026-14428 insufficient input validation in Dawn — Edge (Chromium-based) inherits this GPU/graphics pipeline vulnerability. Ensure Edge is on the latest stable release across your managed fleet.
CVE-2026-15308 HTMLParser CPU-exhaustion DoS — Repeated unterminated markup declarations can exhaust CPU. Relevant for any Python-based backend services or automation tooling parsing untrusted HTML.
Collaboration & Productivity
Upcoming retirement of OWA Light in Exchange Server [GA] — Microsoft will retire and disable OWA Light in a future Exchange Server cumulative update; no specific date is given yet, but the direction is firm. Audit your organization for any users, browser policies, or helpdesk documentation pointing to the
?layout=lightURL parameter or the light client bookmark, and redirect them to standard Outlook on the web. Update internal training materials and review whether any accessibility accommodations were served by OWA Light that now need an alternative path.Solutions for document-centric business processes - Portal Systems - SharePoint Partner Spotlight [GA] — Portal Systems AG showcases ECM solutions built on SPFx for SharePoint and Microsoft 365. Worth reviewing if your organization is evaluating document-centric workflow tooling on top of SharePoint rather than a third-party ECM platform.
Proven intranet framework - Involv Intranet - SharePoint Partner Spotlight [GA] — Involv Intranet provides a branded, mobile-ready intranet built on SPFx with 50-plus configurable components. If your organization has an intranet refresh on the roadmap, this is a reference point for what the SPFx partner ecosystem can deliver out of the box.
Streamlining business processes with Microsoft 365 - ShareCloud - SharePoint Partner Spotlight [GA] — ShareCloud demonstrates productized SharePoint-based business application solutions built on Microsoft 365 and Power Platform. Relevant context if you are evaluating partners to extend SharePoint into line-of-business workflows without custom development overhead.
Security & Compliance
CVE-2026-40468 Heap buffer overflow in gawk [GA] — Heap buffer overflow in gawk published by MSRC this week. Inventory managed Linux endpoints and any Windows Subsystem for Linux environments where gawk may be installed, and apply vendor patches when available.
CVE-2026-40469 Heap buffer overflow in gawk [GA] — A second heap buffer overflow CVE in gawk, tracked separately from CVE-2026-40468. Treat both together when assessing exposure; patch the same gawk installations identified for the previous CVE.
CVE-2026-40553 Stack-based buffer overflow in gawk [GA] — Stack-based buffer overflow in gawk completes a trio of gawk CVEs this week. Stack overflows carry elevated exploitation risk relative to heap variants; prioritize remediation accordingly.
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input [GA] — Unlimited input during decompression or parsing in node-tar can cause a denial of service. Identify any CI/CD pipelines, automation agents, or Node.js services consuming node-tar and validate they are running a patched version.
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion [GA] — Type confusion in PAX numeric path handling causes a process crash in node-tar. This pairs with CVE-2026-59873; remediate both in the same pass when updating node-tar dependencies.
CVE-2026-15308 Incremental HTMLParser feed() CPU-exhaustion DoS [GA] — Repeated unterminated markup declarations passed to the incremental HTMLParser feed() method can exhaust CPU. Review Python-based services, automation scripts, or backend tools that parse untrusted HTML and update the affected library once a patch is released.
Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn [GA] — Insufficient input validation in Chromium’s Dawn graphics layer affects Microsoft Edge. Confirm your Edge deployment is on the current stable channel build; if you manage Edge updates via Intune or a software update policy, validate compliance reports show no outdated versions.
Action Required
Upcoming retirement of OWA Light in Exchange Server [GA] — Plan within 30 days: No specific retirement date is published yet, but Microsoft has confirmed this feature will be disabled in an upcoming Exchange Server update. Identify users relying on OWA Light, update helpdesk documentation, remove or redirect any internal bookmarks to the light client URL, and confirm that any accessibility accommodations previously handled by OWA Light have a supported replacement in modern Outlook on the web.
CVE-2026-40553 Stack-based buffer overflow in gawk [GA] — Patch when available: Stack-based overflow in gawk is the highest-risk of the three gawk CVEs this week. Inventory gawk across managed Linux endpoints, WSL environments, and any server workloads, and prioritize patching once the upstream fix is available in your distribution’s package repository.
CVE-2026-59871 and CVE-2026-59873 node-tar vulnerabilities [GA] — Audit and patch within 30 days: Both node-tar CVEs affect process stability and availability. Scan your Node.js dependency trees across CI/CD pipelines and deployed services for node-tar versions below the patched release, and update as part of your next dependency maintenance window.
Documentation Updates
Identity & Access
OAuth credentials added for Netskope integration - New OAuth credential documentation supports Netskope integration with Entra ID, relevant if Netskope is part of your SSE stack.
Custom PAC files documentation added - New documentation covers custom PAC (proxy auto-config) file configuration, useful if you’re routing traffic through Global Secure Access via explicit proxy.
SMS and Voice MFA retirement article added - A new dedicated article covers the SMS and Voice MFA retirement, giving admins a single reference for timeline, impact, and migration steps.
Retired OAuth authorization code grant removed from SCIM authorization table - The SCIM authorization documentation no longer lists the retired OAuth authorization code grant, reflecting current supported options.
Catalog Access Reviews added to guest billing table - Guest billing documentation now includes Catalog Access Reviews, relevant if you manage external identity governance costs.
Endpoint & Device Management
SQL collation/config check added before Modify SQL Server configuration - New guidance adds a SQL collation and configuration check as a prerequisite step before modifying SQL Server configuration during site maintenance.
Supported apps revised for Multiple Managed Accounts — Outlook - The supported-apps list for the Multiple Managed Accounts feature has been revised for Outlook, worth checking if you’re piloting this BYOD capability.
Security & Compliance
- Client Analyzer shipped version instructions clarified - Instructions for running the Client Analyzer shipped version have been clarified, useful if you’re troubleshooting Defender client health.
Sources
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40468
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40469
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40553
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59873
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59871
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15308
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-14428
- https://www.youtube.com/shorts/0heeppCYrmM
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/solutions-for-document-centric-business-processes-portal-systems/ba-p/4515217
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/proven-intranet-framework-involv-intranet-sharepoint-partner/ba-p/4519241
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/streamlining-business-processes-with-microsoft-365-sharecloud/ba-p/4533560
- https://techcommunity.microsoft.com/t5/exchange-team-blog/upcoming-retirement-of-owa-light-in-exchange-server/ba-p/4534943
- https://www.youtube.com/shorts/YImum6f4Z2w
- https://github.com/MicrosoftDocs/entra-docs/commit/b2f01e7925e33723fee0758775ddd402e763fd8d
- https://github.com/MicrosoftDocs/entra-docs/commit/032e76b3efffcfeb5085040a570cc2da485f9994
- https://github.com/MicrosoftDocs/entra-docs/commit/fe2d7fee3776e13c070d9a1d780bb5857825ebf4
- https://github.com/MicrosoftDocs/entra-docs/commit/baf944d20533641128e0a37ce7ae66e7bca24222
- https://github.com/MicrosoftDocs/entra-docs/commit/c30533c792380fe00bfbc4ad74c2069bc19ac51f
- https://github.com/MicrosoftDocs/memdocs/commit/bd54eea18d442412e7bc78ab822a1716bbe79d45
- https://github.com/MicrosoftDocs/memdocs/commit/60807614c5668ec0d7567ec1591d675c277b46e6
- https://github.com/MicrosoftDocs/defender-docs/commit/862d3f62f48270e976c2492cfce1c0b82a55721e
