<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>TrustDigital Live</title>
<link>https://www.trustdigital.net/live</link>
<atom:link href="https://www.trustdigital.net/live-feed.xml" rel="self" type="application/rss+xml"/>
<description>Actively exploited vulnerabilities, vendor advisories, Microsoft changes, and end-of-support deadlines — filtered to what matters for businesses on the modern Microsoft stack, by the TrustDigital team.</description>
<language>en-us</language>
<lastBuildDate>Tue, 15 Sep 2026 17:06:41 GMT</lastBuildDate>
<item>
<title>[CISA Advisory] Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers</title>
<link>https://www.cisa.gov/resources-tools/resources/protecting-tokens-and-assertions-forgery-theft-and-misuse-implementation-recommendations-agencies</link>
<guid isPermaLink="false">https://www.cisa.gov/resources-tools/resources/protecting-tokens-and-assertions-forgery-theft-and-misuse-implementation-recommendations-agencies</guid>
<pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
<description>Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and author — Who should care: Business owners and office managers should pay attention because safeguarding digital identities and access controls is crucial for protecting company data and preventing unauthorized access.</description>
</item>
<item>
<title>[Vendor Advisory] Cisco: Cisco IOS XR Software Security Hardening Release: September 2026</title>
<link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Software%20Security%20Hardening%20Release:%20September%202026%26vs_k=1</link>
<guid isPermaLink="false">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Software%20Security%20Hardening%20Release:%20September%202026%26vs_k=1</guid>
<pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
<description>As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These v — Who should care: Network administrators should pay attention to this update because it helps protect their systems from vulnerabilities, ensuring smoother operations and reducing the risk of potential disruptions. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Actively Exploited] Cisco Secure Email Gateway: CVE-2026-76461</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-76461</link>
<guid isPermaLink="false">CVE-2026-76461</guid>
<pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
<description>Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. — Who should care: IT managers and business owners should pay attention because this vulnerability could allow attackers to gain control over your email system, potentially compromising sensitive company data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds One Known Exploited Vulnerability to Catalog</title>
<link>https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog</guid>
<pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
<description>CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses sign — Who should care: Business owners should pay attention to this new vulnerability, as it highlights a potential risk to their email security that could lead to data breaches.</description>
</item>
<item>
<title>[Microsoft Change] One month until Office LTSC 2021 end of support</title>
<link>https://techcommunity.microsoft.com/t5/microsoft-365-blog/one-month-until-office-ltsc-2021-end-of-support/ba-p/4554417</link>
<guid isPermaLink="false">https://techcommunity.microsoft.com/t5/microsoft-365-blog/one-month-until-office-ltsc-2021-end-of-support/ba-p/4554417</guid>
<pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
<description>As previously communicated , support for Office LTSC 2021 will end on October 13, 2026 . After that date, no further updates, security fixes, or technical support will be available for this version of Office. While the applications may continue to function, using unsupported software could lead to p — Who should care: Business owners should note that after October 13, 2026, using Office LTSC 2021 without support may expose their company to security risks and compliance issues. — What to do: Ask us what this changes for your tenant and when to act.</description>
</item>
<item>
<title>[Vendor Advisory] Cisco: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026</title>
<link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Gateway%20and%20Secure%20Email%20and%20Web%20Manager%20Security%20Hardening%20Release:%20September%202026%26vs_k=1</link>
<guid isPermaLink="false">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Gateway%20and%20Secure%20Email%20and%20Web%20Manager%20Security%20Hardening%20Release:%20September%202026%26vs_k=1</guid>
<pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
<description>As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple in — Who should care: Small and mid-size business owners should pay attention because this update helps protect their email systems from potential vulnerabilities, ensuring safer communication and data handling. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Actively Exploited] ConnectWise ScreenConnect: CVE-2026-84869</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-84869</link>
<guid isPermaLink="false">CVE-2026-84869</guid>
<pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
<description>ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. — Who should care: Business owners using ConnectWise ScreenConnect should be aware of this vulnerability, as it could allow unauthorized access to sensitive information during remote sessions. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] GitLab Community Edition and Enterprise Edition: CVE-2026-85706</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-85706</link>
<guid isPermaLink="false">CVE-2026-85706</guid>
<pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
<description>GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. — Who should care: Business owners using GitLab should prioritize updates, as this vulnerability could allow unauthorized access to sensitive company files. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds Three Known Exploited Vulnerabilities to Catalog   </title>
<link>https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog</guid>
<pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
<description>CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 Conne — Who should care: Business owners should monitor these vulnerabilities to ensure their software is secure, as active exploitation could lead to data breaches and operational disruptions.</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds One Known Exploited Vulnerability to Catalog   </title>
<link>https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog</guid>
<pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
<description>CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber — Who should care: Business owners and office managers should monitor this vulnerability as it may expose your company's GitLab software to attacks, potentially compromising sensitive data.</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds Two Known Exploited Vulnerabilities to Catalog</title>
<link>https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog</guid>
<pubDate>Thu, 10 Sep 2026 12:00:00 GMT</pubDate>
<description>CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Del — Who should care: Small to mid-size business owners should pay attention to these vulnerabilities, as they could lead to unauthorized access and compromise their network security if not addressed promptly.</description>
</item>
<item>
<title>[Actively Exploited] Citrix NetScaler: CVE-2026-19490</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-19490</link>
<guid isPermaLink="false">CVE-2026-19490</guid>
<pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
<description>Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may b — Who should care: Companies using Citrix NetScaler should review their configurations immediately, as this vulnerability could allow unauthorized access to sensitive data and systems. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Fortinet Multiple Products: CVE-2025-25249</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2025-25249</link>
<guid isPermaLink="false">CVE-2025-25249</guid>
<pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
<description>Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. — Who should care: IT managers and business owners should pay attention because this vulnerability could allow attackers to take control of critical systems, potentially disrupting operations and compromising sensitive data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Google Chromium V8: CVE-2026-87491</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-87491</link>
<guid isPermaLink="false">CVE-2026-87491</guid>
<pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
<description>Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Ed — Who should care: Small and mid-size business owners should pay attention because this vulnerability could allow attackers to exploit web browsers, potentially compromising sensitive company data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management: CVE-2026-20079</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-20079</link>
<guid isPermaLink="false">CVE-2026-20079</guid>
<pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
<description>Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files o — Who should care: Business owners using Cisco firewall products should be aware of this vulnerability, as it could allow unauthorized access to their network and sensitive data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[CISA Advisory] CISA Adds Four Known Exploited Vulnerabilities to Catalog</title>
<link>https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog</link>
<guid isPermaLink="false">https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog</guid>
<pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
<description>CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or — Who should care: Small and mid-sized business owners should be aware of these vulnerabilities to ensure their IT systems are updated and protected from potential attacks.</description>
</item>
<item>
<title>[Actively Exploited] Adobe Commerce and Magento: CVE-2026-75650</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-75650</link>
<guid isPermaLink="false">CVE-2026-75650</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. — Who should care: Business owners using Adobe Commerce or Magento should be aware of this vulnerability, as it could allow attackers to take control of their online stores. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Microsoft Windows: CVE-2026-81963</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-81963</link>
<guid isPermaLink="false">CVE-2026-81963</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. — Who should care: Business owners and office managers should pay attention because this Windows vulnerability could allow attackers to gain full control of your systems, risking sensitive company data. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] Microsoft Windows: CVE-2026-85880</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-85880</link>
<guid isPermaLink="false">CVE-2026-85880</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. — Who should care: Business owners should pay attention because this vulnerability could allow attackers to gain higher access to your systems, potentially compromising sensitive company information. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Microsoft] Microsoft security updates: 2026 Sep</title>
<link>https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep</link>
<guid isPermaLink="false">msrc-2026-Sep</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>Microsoft’s monthly security release. If we manage your patching, these are already scheduled for your environment. — Who should care: Business owners should note the latest Microsoft updates to ensure their systems remain secure and compliant, especially if they rely on managed IT services for patching.</description>
</item>
<item>
<title>[Vendor Advisory] Fortinet: Arbitrary process termination from exposed minifilter communication port</title>
<link>https://fortiguard.fortinet.com/psirt/FG-IR-26-165</link>
<guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-165</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. Revised on 2026-09-08 00:00:00 — Who should care: IT managers and business owners should be aware of this vulnerability as it could allow attackers to disrupt critical processes in your systems, impacting business operations. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Vendor Advisory] Fortinet: Broken Access control on Websocket streams</title>
<link>https://fortiguard.fortinet.com/psirt/FG-IR-26-164</link>
<guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-164</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00 — Who should care: Business owners should be aware of this vulnerability in Fortinet products, as it could allow unauthorized access to sensitive information, impacting data security and trust. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Vendor Update] CrowdStrike: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs</title>
<link>https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/</link>
<guid isPermaLink="false">https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<description>Who should care: Business owners and office managers should be aware that critical vulnerabilities have been identified, as unpatched software can lead to security breaches affecting company data and operations. — What to do: Ask us whether this applies to your environment.</description>
</item>
<item>
<title>[Actively Exploited] Google Chromium V8: CVE-2026-85046</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-85046</link>
<guid isPermaLink="false">CVE-2026-85046</guid>
<pubDate>Fri, 04 Sep 2026 12:00:00 GMT</pubDate>
<description>Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, an — Who should care: Business owners and office managers should pay attention because this vulnerability could expose your company's web browsers to attacks, risking sensitive data and disrupting operations. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Actively Exploited] SonicWall SMA1000 Appliances: CVE-2026-83548</title>
<link>https://nvd.nist.gov/vuln/detail/CVE-2026-83548</link>
<guid isPermaLink="false">CVE-2026-83548</guid>
<pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
<description>SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. — Who should care: Business owners using SonicWall SMA1000 appliances should be aware of this vulnerability, as it could allow unauthorized access to sensitive company data and operations. — What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage</description>
</item>
<item>
<title>[Microsoft Change] Microsoft Entra: passkeys become the default Sept 1, 2026 — SMS and voice authentication retire Feb 1, 2027</title>
<link>https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement</link>
<guid isPermaLink="false">pinned-entra-sms-voice-retirement</guid>
<pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
<description>Two-phase change for every Entra ID tenant: on September 1, 2026, users still using SMS or voice codes get automatically enabled for passkeys and prompted to register one. On February 1, 2027, Microsoft-provided SMS and voice authentication retires entirely — tenants that haven't moved to phishing-resistant methods (passkeys, Windows Hello, FIDO2 keys, Authenticator) risk sign-in disruptions. — Who should care: Business owners should prepare for the shift to passkeys by 2026 to ensure smooth access for employees, as reliance on SMS and voice authentication will end in early 2027. — What to do: Ask us to inventory who in your tenant still signs in with SMS or voice codes and plan the migration before September.</description>
</item>
<item>
<title>[Microsoft Change] Update Health in Cloud Update is now Generally Available</title>
<link>https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-health-in-cloud-update-is-now-generally-available/ba-p/4523063</link>
<guid isPermaLink="false">https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-health-in-cloud-update-is-now-generally-available/ba-p/4523063</guid>
<pubDate>Wed, 27 May 2026 12:00:00 GMT</pubDate>
<description>Keeping Microsoft 365 Apps up to date is essential for security, reliability, and access to new features. When an update does not complete successfully, however, identifying the issue and understanding its impact across devices can take time. Today, we’re announcing general availability of update he — Who should care: Business owners and office managers should pay attention to this update because keeping Microsoft 365 Apps current helps protect your company and ensures your team has the latest features for productivity. — What to do: Ask us what this changes for your tenant and when to act.</description>
</item>
<item>
<title>[Microsoft Change] Only 6 months until Office LTSC 2021 end of support – are you ready?</title>
<link>https://techcommunity.microsoft.com/t5/microsoft-365-blog/only-6-months-until-office-ltsc-2021-end-of-support-are-you/ba-p/4509673</link>
<guid isPermaLink="false">https://techcommunity.microsoft.com/t5/microsoft-365-blog/only-6-months-until-office-ltsc-2021-end-of-support-are-you/ba-p/4509673</guid>
<pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
<description>Continuing to use software after end of support can leave your devices vulnerable to potential security threats, productivity losses, and compliance issues. That’s why it’s important to know that in just six months, on October 13, 2026 , support will end for Office LTSC 2021 suites and standalone ap — Who should care: Business owners and office managers should prepare for the end of support for Office LTSC 2021 in six months to avoid security risks and ensure ongoing productivity. — What to do: Ask us what this changes for your tenant and when to act.</description>
</item>
<item>
<title>[End of Support] Windows 11 24H2 (W): support ends 10/13/2026</title>
<link>https://endoflife.date/windows</link>
<guid isPermaLink="false">eol-windows-11-24h2-w</guid>
<pubDate>Tue, 13 Oct 2026 12:00:00 GMT</pubDate>
<description>After 10/13/2026, Windows 11 24H2 (W) stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should plan to upgrade Windows 11 before October 2026 to ensure continued security updates and protect their company from vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Windows 10 1607 (E): support ends 10/13/2026</title>
<link>https://endoflife.date/windows</link>
<guid isPermaLink="false">eol-windows-10-1607-e-lts</guid>
<pubDate>Tue, 13 Oct 2026 12:00:00 GMT</pubDate>
<description>After 10/13/2026, Windows 10 1607 (E) stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should plan to upgrade Windows 10 1607 before October 2026 to ensure continued security and protection against vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Microsoft Office 2021: support ends 10/13/2026</title>
<link>https://endoflife.date/office</link>
<guid isPermaLink="false">eol-office-2021</guid>
<pubDate>Tue, 13 Oct 2026 12:00:00 GMT</pubDate>
<description>After 10/13/2026, Microsoft Office 2021 stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should plan to upgrade Microsoft Office 2021 before October 2026 to ensure ongoing security and protection against vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Windows 11 23H2 (E): support ends 11/10/2026</title>
<link>https://endoflife.date/windows</link>
<guid isPermaLink="false">eol-windows-11-23h2-e</guid>
<pubDate>Tue, 10 Nov 2026 12:00:00 GMT</pubDate>
<description>After 11/10/2026, Windows 11 23H2 (E) stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners and office managers should prepare for the Windows 11 upgrade before November 2026 to maintain security and protect company data from vulnerabilities. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
<item>
<title>[End of Support] Windows 10 21H2 (E): support ends 1/12/2027</title>
<link>https://endoflife.date/windows</link>
<guid isPermaLink="false">eol-windows-10-21h2-e-lts</guid>
<pubDate>Tue, 12 Jan 2027 12:00:00 GMT</pubDate>
<description>After 1/12/2027, Windows 10 21H2 (E) stops receiving security updates. Plan the upgrade before the deadline, not after. — Who should care: Business owners should note that after January 2027, Windows 10 21H2 will no longer receive security updates, increasing vulnerability to cyber threats. — What to do: Talk to us about upgrade planning if this is in your environment.</description>
</item>
</channel>
</rss>
