You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
on prem security
About this tag
On-prem security discussions on WindowsForum.com focus on patching and maintaining Microsoft server products that run in local data centers. Recent threads cover critical vulnerabilities in SharePoint Server and Exchange Server, emphasizing the need for timely updates. Topics include CVE-2026-35439, a remote code execution flaw in SharePoint Server Subscription Edition, 2019, and 2016, which requires immediate patching despite Microsoft's lower exploitation assessment. Exchange Server on-premise admins are advised on months without security updates and the importance of Extended Security Updates for older versions. The tag highlights the ongoing responsibility of securing on-premises infrastructure against evolving threats.
Microsoft disclosed CVE-2026-35439 on May 12, 2026, as an Important-rated Microsoft SharePoint Server remote code execution vulnerability caused by deserialization of untrusted data, affecting SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016...
No Exchange Server Security Updates for January 2026 — What on‑premise Exchange admins need to know and do now
On January 13, 2026 Microsoft’s Exchange Team published a short but important bulletin: there are no security releases for any version of Exchange Server in January 2026. The post also...