<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>TrustDigital Live</title>
<link>https://www.trustdigital.net/live</link>
<atom:link href="https://www.trustdigital.net/live-feed.xml" rel="self" type="application/rss+xml"/>
<description>Actively exploited vulnerabilities, vendor advisories, Microsoft changes, and end-of-support deadlines — filtered to what matters for businesses on the modern Microsoft stack, by the TrustDigital team.</description>
<language>en-us</language>
<lastBuildDate>Sat, 01 Aug 2026 08:36:32 GMT</lastBuildDate>
<item>
<title>[Vendor Advisory] Cisco: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability</title>
<link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Authentication%20Bypass%20Vulnerability%26vs_k=1</link>
<guid isPermaLink="false">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Authentication%20Bypass%20Vulnerability%26vs_k=1</guid>
<pubDate>Fri, 31 Jul 2026 12:00:00 GMT</pubDate>
<description>A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due t — Who should care: IT managers and business owners should pay attention to this vulnerability as it could allow unauthorized access to critical systems, potentially compromising sensitive company data. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Vendor Advisory] Cisco: Cisco Secure Firewall Management Center Software Static Credential Vulnerability</title>
<link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Static%20Credential%20Vulnerability%26vs_k=1</link>
<guid isPermaLink="false">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Static%20Credential%20Vulnerability%26vs_k=1</guid>
<pubDate>Fri, 31 Jul 2026 12:00:00 GMT</pubDate>
<description>A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presenc — Who should care: Business owners using Cisco firewall products should be aware of this vulnerability, as it could expose sensitive company data to unauthorized access. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[CISA Advisory] Open Source Software: Security Principles and Practices</title>
<link>https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices</link>
<guid isPermaLink="false">https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices</guid>
<pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate>
<description>Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management — Who should care: Business owners and office managers should pay attention to this guidance as it helps ensure the safe use of open source software, which is essential for protecting your company's systems and data.</description>
</item>
<item>
<title>[CISA Advisory] CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs</title>
<link>https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs</guid>
<pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate>
<description>CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational tech — Who should care: Water and wastewater system managers should take note, as protecting operational technology from cyber threats is crucial to ensure safe and reliable services for communities.</description>
</item>
<item>
<title>[Actively Exploited] Cisco Secure Firewall Management Center (FMC): CVE-2026-20316</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-20316</link>
<guid isPermaLink="false">CVE-2026-20316</guid>
<pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
<description>Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impa — Who should care: Small and mid-size business owners should be aware of this vulnerability, as it could allow unauthorized access to sensitive data, potentially compromising their operations and customer trust. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[CISA Advisory] 2026 Minimum Elements for a Software Bill of Materials (SBOM)</title>
<link>https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom</link>
<guid isPermaLink="false">https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom</guid>
<pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
<description>CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM) , that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Inf — Who should care: Business owners and managers should pay attention to this advisory as it outlines essential software documentation requirements that can enhance security and compliance for their company's software assets.</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds One Known Exploited Vulnerability to Catalog </title>
<link>https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog</guid>
<pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
<description>CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious c — Who should care: Business owners and office managers should pay attention to this vulnerability as it highlights a security risk that could expose their systems to attacks if not addressed promptly.</description>
</item>
<item>
<title>[CISA Advisory] CI Fortify – Advice for isolating vital systems</title>
<link>https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems</link>
<guid isPermaLink="false">https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems</guid>
<pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
<description>CI Fortify – Advice for isolating vital systems CI Fortify – Advice for isolating vital systems (PDF) CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international partners, released joint guid — Who should care: Business owners should pay attention to this guidance on isolating vital systems to protect their critical operations from potential cyber threats.</description>
</item>
<item>
<title>[Actively Exploited] Fortinet FortiOS: CVE-2025-68686</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2025-68686</link>
<guid isPermaLink="false">CVE-2025-68686</guid>
<pubDate>Mon, 27 Jul 2026 12:00:00 GMT</pubDate>
<description>Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacke — Who should care: Small and mid-size business owners should pay attention because this vulnerability could let unauthorized users access sensitive information, potentially compromising your company's data security. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
<link>https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog</guid>
<pubDate>Mon, 27 Jul 2026 12:00:00 GMT</pubDate>
<description>CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Com — Who should care: Business owners should pay attention because these vulnerabilities could put sensitive company information at risk, highlighting the importance of keeping software updated and secure.</description>
</item>
<item>
<title>[Actively Exploited] Microsoft SharePoint: CVE-2026-50522</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-50522</link>
<guid isPermaLink="false">CVE-2026-50522</guid>
<pubDate>Wed, 22 Jul 2026 12:00:00 GMT</pubDate>
<description>Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. — Who should care: Business owners using Microsoft SharePoint should be aware of a vulnerability that could let attackers run harmful code remotely, potentially compromising sensitive company data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Vendor Update] Check Point: Security Advisory – Action Required – July 2026 Security Update</title>
<link>https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/</link>
<guid isPermaLink="false">https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/</guid>
<pubDate>Wed, 22 Jul 2026 12:00:00 GMT</pubDate>
<description>As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a r — Who should care: Business owners and office managers should pay attention to this update as it includes important security fixes that help protect your company's network from potential threats. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Actively Exploited] WordPress Core: CVE-2026-60137</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-60137</link>
<guid isPermaLink="false">CVE-2026-60137</guid>
<pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate>
<description>WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. — Who should care: Website managers using WordPress should pay attention, as this vulnerability could allow attackers to take control of their site without needing a password. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] WordPress Core: CVE-2026-63030</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-63030</link>
<guid isPermaLink="false">CVE-2026-63030</guid>
<pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate>
<description>WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. — Who should care: Small and mid-sized business owners using WordPress should be aware of this vulnerability, as it could allow attackers to compromise their websites and access sensitive data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Microsoft SharePoint: CVE-2026-58644</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-58644</link>
<guid isPermaLink="false">CVE-2026-58644</guid>
<pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate>
<description>Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. — Who should care: Business owners using Microsoft SharePoint should be aware of a vulnerability that could allow unauthorized access to their systems, potentially compromising sensitive information. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Fortinet FortiSandbox: CVE-2026-25089</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-25089</link>
<guid isPermaLink="false">CVE-2026-25089</guid>
<pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate>
<description>Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. — Who should care: Business owners using Fortinet products should be aware of this vulnerability, as it could allow attackers to gain unauthorized access to their systems. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Fortinet FortiSandbox: CVE-2026-39808</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-39808</link>
<guid isPermaLink="false">CVE-2026-39808</guid>
<pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate>
<description>Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. — Who should care: Small to mid-size business owners should pay attention to this vulnerability as it could allow attackers to gain unauthorized access to their systems, risking sensitive data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Microsoft Active Directory Federation Services: CVE-2026-56155</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-56155</link>
<guid isPermaLink="false">CVE-2026-56155</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. — Who should care: Business owners should be aware of this vulnerability as it could allow attackers to gain unauthorized access to sensitive company data, potentially compromising security and trust. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Microsoft SharePoint Server: CVE-2026-56164</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-56164</link>
<guid isPermaLink="false">CVE-2026-56164</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. — Who should care: Small and mid-size business owners should be aware that a vulnerability in Microsoft SharePoint could allow unauthorized access to sensitive data, potentially compromising their operations. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] SonicWall SMA1000 Appliances: CVE-2026-15409</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-15409</link>
<guid isPermaLink="false">CVE-2026-15409</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. — Who should care: IT managers and business owners should monitor this vulnerability, as it could expose sensitive data or systems to unauthorized access if not addressed promptly. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] SonicWall SMA1000 Appliances: CVE-2026-15410</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-15410</link>
<guid isPermaLink="false">CVE-2026-15410</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. — Who should care: Business owners using SonicWall SMA1000 appliances should be aware of this vulnerability, as it could allow unauthorized access to their systems and compromise sensitive data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Microsoft] Microsoft security updates: 2026 Jul</title>
<link>https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul</link>
<guid isPermaLink="false">msrc-2026-Jul</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>Microsoft’s monthly security release. If we manage your patching, these are already scheduled for your environment. — Who should care: Business owners and office managers should note that Microsoft’s security updates help protect your systems from vulnerabilities, ensuring your operations run smoothly and securely.</description>
</item>
<item>
<title>[Vendor Advisory] Fortinet: Buffer overread in authd and wad daemon</title>
<link>https://fortiguard.fortinet.com/psirt/FG-IR-26-154</link>
<guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-154</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00 — Who should care: IT managers should pay attention because this vulnerability could potentially expose sensitive information, impacting the security of your network devices. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Vendor Advisory] Fortinet: Cross-Site Scripting in Domain parameter</title>
<link>https://fortiguard.fortinet.com/psirt/FG-IR-26-149</link>
<guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-149</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00 — Who should care: Business owners using Fortinet products should review this advisory to ensure their systems are secure and prevent unauthorized access to sensitive information. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Microsoft Change] Microsoft Entra: passkeys become the default Sept 1, 2026 — SMS and voice authentication retire Feb 1, 2027</title>
<link>https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement</link>
<guid isPermaLink="false">pinned-entra-sms-voice-retirement</guid>
<pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
<description>Two-phase change for every Entra ID tenant: on September 1, 2026, users still using SMS or voice codes get automatically enabled for passkeys and prompted to register one. On February 1, 2027, Microsoft-provided SMS and voice authentication retires entirely — tenants that haven't moved to phishing-resistant methods (passkeys, Windows Hello, FIDO2 keys, Authenticator) risk sign-in disruptions. — Who should care: Business owners should prepare for the shift to passkeys by 2026 to ensure smooth access for employees, as reliance on SMS and voice authentication will end in early 2027. — What to do: Ask us to inventory who in your tenant still signs in with SMS or voice codes and plan the migration before September.</description>
</item>
<item>
<title>[Microsoft Change] Update Health in Cloud Update is now Generally Available</title>
<link>https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-health-in-cloud-update-is-now-generally-available/ba-p/4523063</link>
<guid isPermaLink="false">https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-health-in-cloud-update-is-now-generally-available/ba-p/4523063</guid>
<pubDate>Wed, 27 May 2026 12:00:00 GMT</pubDate>
<description>Keeping Microsoft 365 Apps up to date is essential for security, reliability, and access to new features. When an update does not complete successfully, however, identifying the issue and understanding its impact across devices can take time. Today, we’re announcing general availability of update he — Who should care: Business owners and office managers should pay attention to this update because keeping Microsoft 365 Apps current helps protect your company and ensures your team has the latest features for productivity. — What to do: Ask us what this changes for your tenant and when to act.</description>
</item>
<item>
<title>[Microsoft Change] Only 6 months until Office LTSC 2021 end of support – are you ready?</title>
<link>https://techcommunity.microsoft.com/t5/microsoft-365-blog/only-6-months-until-office-ltsc-2021-end-of-support-are-you/ba-p/4509673</link>
<guid isPermaLink="false">https://techcommunity.microsoft.com/t5/microsoft-365-blog/only-6-months-until-office-ltsc-2021-end-of-support-are-you/ba-p/4509673</guid>
<pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
<description>Continuing to use software after end of support can leave your devices vulnerable to potential security threats, productivity losses, and compliance issues. That’s why it’s important to know that in just six months, on October 13, 2026 , support will end for Office LTSC 2021 suites and standalone ap — Who should care: Business owners and office managers should prepare for the end of support for Office LTSC 2021 in six months to avoid security risks and ensure ongoing productivity. — What to do: Ask us what this changes for your tenant and when to act.</description>
</item>
<item>
<title>[End of Support] SQL Server 2016 SP3 Azure Connect Pack: support has ended</title>
<link>https://endoflife.date/mssqlserver</link>
<guid isPermaLink="false">eol-mssqlserver-13.0-sp3-acp</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>Security updates for SQL Server 2016 SP3 Azure Connect Pack stopped on 7/14/2026. Systems still running it are accumulating unpatched risk. — Who should care: Business owners using SQL Server 2016 should consider upgrading soon, as unsupported software can expose your company to security risks without updates. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] SQL Server 2016 SP3: support has ended</title>
<link>https://endoflife.date/mssqlserver</link>
<guid isPermaLink="false">eol-mssqlserver-13.0-sp3</guid>
<pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
<description>Security updates for SQL Server 2016 SP3 stopped on 7/14/2026. Systems still running it are accumulating unpatched risk. — Who should care: Business owners using SQL Server 2016 should be aware that without support, their systems are vulnerable to security risks that could impact operations and data safety. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Windows 11 24H2 (W): support ends 10/13/2026</title>
<link>https://endoflife.date/windows</link>
<guid isPermaLink="false">eol-windows-11-24h2-w</guid>
<pubDate>Tue, 13 Oct 2026 12:00:00 GMT</pubDate>
<description>After 10/13/2026, Windows 11 24H2 (W) stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should plan to upgrade Windows 11 before October 2026 to ensure continued security updates and protect their company from vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Windows 10 1607 (E): support ends 10/13/2026</title>
<link>https://endoflife.date/windows</link>
<guid isPermaLink="false">eol-windows-10-1607-e-lts</guid>
<pubDate>Tue, 13 Oct 2026 12:00:00 GMT</pubDate>
<description>After 10/13/2026, Windows 10 1607 (E) stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should plan to upgrade Windows 10 1607 before October 2026 to ensure continued security and protection against vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Microsoft Office 2021: support ends 10/13/2026</title>
<link>https://endoflife.date/office</link>
<guid isPermaLink="false">eol-office-2021</guid>
<pubDate>Tue, 13 Oct 2026 12:00:00 GMT</pubDate>
<description>After 10/13/2026, Microsoft Office 2021 stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should plan to upgrade Microsoft Office 2021 before October 2026 to ensure ongoing security and protection against vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
</channel>
</rss>
