Collab365 SpacesCollab365 Spaces
SpacesBoardsPricingAcademy membersHow It Works
Collab365 Spaces

AI changes work. Know what to do.

Follow Collab365

FacebookLinkedInInstagramX (Twitter)TikTokYouTube
Excellent on TrustpilotTrustScore 4.5/514 reviews

Platform

  • Explore Spaces
  • Create Account
  • Spaces Roadmap
  • For Teams

Company

  • How We're Surviving AI
  • Blog
  • Academy members
  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Cookie Policy
Platform
  • Explore Spaces
  • Create Account
  • Spaces Roadmap
  • For Teams
Company
  • How We're Surviving AI
  • Blog
  • Academy members
  • About
  • Contact
Legal
  • Privacy
  • Terms
  • Cookie Policy

© 2026 Collab365 Spaces Limited. All rights reserved.

Badhan Ct, Castle St, Hadley, Telford, Shropshire, TF1 5QX, UK

AI changes work. Know what to do.
See what is included

Microsoft ships September security update for SharePoint Server Subscription Edition

Reviewed by Helen JonesLast review 10 Sept 2026
Microsoft ships September security update for SharePoint Server Subscription Edition

On 8 September 2026 Microsoft released KB5002908 for SharePoint Server Subscription Edition, build 16.0.20326.20136. It is the monthly security cumulative update for the only still-supported on-premises SharePoint Server line. The package addresses information disclosure, remote code execution, spoofing, security feature bypass, elevation of privilege, and related Word remote code execution issues. Non-security changes disable GetDataFromDataSourceControl SOAP and ExecuteProxyUpdates starting with this CU, alongside accessibility and UI fixes. It applies only to Subscription Edition. SharePoint Server 2016 and 2019 already left support earlier in 2026 with no extended security updates.

Before this cycle, a hybrid or on-prem Subscription Edition farm could stay on an earlier CU and still look operational while carrying unpatched server-side paths that attackers and auditors care about. Small IT teams often treat on-prem SharePoint as background infrastructure next to Teams sprawl and the cloud intranet, so patch windows slip until something breaks or an audit lands. After KB5002908, the security baseline for SE moves forward and two legacy data-path features are turned off by design. That is not only a patch day chore. Farms that still lean on older BCS or SOAP-style data source controls can fail after a successful install, which turns a quiet security update into user-facing outages on the same systems that feed hybrid search, intranet pages, or line-of-business lists.

Analysis

Treat this as a change to act on if you still run Subscription Edition, not a cloud admin footnote. Before you approve the CU, list every SE farm build and any remaining BCS, SOAP, or data-source customizations that might call the disabled endpoints, then schedule the update only after that check is done.

Read full story on support.microsoft.com

Source note

Source note

Pulse published by Collab365 Spaces, reviewed by Helen Jones on 10 Sept 2026. Cite as "Microsoft ships September security update for SharePoint Server Subscription Edition", Collab365 Spaces. 3 sources referenced.

spaces.collab365.com/posts/microsoft-ships-september-security-update-for-sharepoint-server-subscription-edition-jb8zunob