You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
on-prem patching
About this tag
On-prem patching discussions on WindowsForum.com focus on applying security updates for Microsoft SharePoint Server vulnerabilities, specifically CVE-2026-45465, CVE-2026-45464, and CVE-2026-45467. These are Important-rated spoofing flaws caused by cross-site scripting, affecting SharePoint Server Subscription Edition, 2019, and 2016. The threads emphasize that SharePoint remains a high-value internal platform, making prompt patching critical even for medium-scored bugs. Administrators are advised to treat these updates seriously due to SharePoint's role as a document hub and identity-adjacent trust broker, despite sparse details from Microsoft on some CVEs. The recurring theme is disciplined, timely on-prem patching to mitigate browser-mediated spoofing risks.
Microsoft published CVE-2026-45465 on June 9, 2026, describing an Important-rated Microsoft SharePoint Server spoofing vulnerability in supported on-premises SharePoint Server editions, caused by cross-site scripting and fixed through security updates for Subscription Edition, SharePoint Server...
Microsoft disclosed CVE-2026-45464 on June 9, 2026, as an Important-rated spoofing vulnerability in SharePoint Server caused by cross-site scripting, affecting SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, with security updates now...
Microsoft has listed CVE-2026-45467 as a Microsoft SharePoint Server spoofing vulnerability in its Security Update Guide as of June 2026, but the public record available to administrators appears to offer more confidence in the flaw’s existence than in its operational details. That distinction...