Top 5 This Week

  1. OWA Light retirement in Exchange Server — Microsoft has announced plans to disable OWA Light in a future Exchange Server update. If any users or helpdesk workflows still rely on the light client, start migration planning now before the update lands.

  2. Three gawk buffer overflow CVEs (CVE-2026-40468, CVE-2026-40469, CVE-2026-40553) — Heap and stack buffer overflows published for gawk. Review whether gawk is present in any managed Linux endpoints or server workloads and track patch availability.

  3. node-tar DoS vulnerabilities (CVE-2026-59873, CVE-2026-59871) — Two CVEs covering decompression/parse DoS and process crash via PAX path type confusion in node-tar. Any build pipelines, automation agents, or services using node-tar need patching.

  4. Chromium CVE-2026-14428 insufficient input validation in Dawn — Edge (Chromium-based) inherits this GPU/graphics pipeline vulnerability. Ensure Edge is on the latest stable release across your managed fleet.

  5. CVE-2026-15308 HTMLParser CPU-exhaustion DoS — Repeated unterminated markup declarations can exhaust CPU. Relevant for any Python-based backend services or automation tooling parsing untrusted HTML.

Apps

  • Upcoming retirement of OWA Light in Exchange Server [GA] — Microsoft will retire and disable OWA Light in a future Exchange Server cumulative update; no specific date is given yet, but the direction is firm. Audit your organization for any users, browser policies, or helpdesk documentation pointing to the ?layout=light URL parameter or the light client bookmark, and redirect them to standard Outlook on the web. Update internal training materials and review whether any accessibility accommodations were served by OWA Light that now need an alternative path.

  • Solutions for document-centric business processes - Portal Systems - SharePoint Partner Spotlight [GA] — Portal Systems AG showcases ECM solutions built on SPFx for SharePoint and Microsoft 365. Worth reviewing if your organization is evaluating document-centric workflow tooling on top of SharePoint rather than a third-party ECM platform.

  • Proven intranet framework - Involv Intranet - SharePoint Partner Spotlight [GA] — Involv Intranet provides a branded, mobile-ready intranet built on SPFx with 50-plus configurable components. If your organization has an intranet refresh on the roadmap, this is a reference point for what the SPFx partner ecosystem can deliver out of the box.

  • Streamlining business processes with Microsoft 365 - ShareCloud - SharePoint Partner Spotlight [GA] — ShareCloud demonstrates productized SharePoint-based business application solutions built on Microsoft 365 and Power Platform. Relevant context if you are evaluating partners to extend SharePoint into line-of-business workflows without custom development overhead.

Visibility & Automation

Action Required

  • Upcoming retirement of OWA Light in Exchange Server [GA] — Plan within 30 days: No specific retirement date is published yet, but Microsoft has confirmed this feature will be disabled in an upcoming Exchange Server update. Identify users relying on OWA Light, update helpdesk documentation, remove or redirect any internal bookmarks to the light client URL, and confirm that any accessibility accommodations previously handled by OWA Light have a supported replacement in modern Outlook on the web.

  • CVE-2026-40553 Stack-based buffer overflow in gawk [GA] — Patch when available: Stack-based overflow in gawk is the highest-risk of the three gawk CVEs this week. Inventory gawk across managed Linux endpoints, WSL environments, and any server workloads, and prioritize patching once the upstream fix is available in your distribution’s package repository.

  • CVE-2026-59871 and CVE-2026-59873 node-tar vulnerabilities [GA] — Audit and patch within 30 days: Both node-tar CVEs affect process stability and availability. Scan your Node.js dependency trees across CI/CD pipelines and deployed services for node-tar versions below the patched release, and update as part of your next dependency maintenance window.