Back to News
SharePoint OnlineSeptember 28, 2026

SharePoint Online Weekly Update — September 28, 2026

A high-severity SharePoint Server vulnerability (CVE-2026-65660) is under active exploitation with a CISA patch deadline landing this week; SPFx 1.24 beta ships Copilot Components with React 18 support; and SharePoint Advanced Management adds an AI governance agent.

Critical: SharePoint Server Vulnerability Under Active Exploitation

The story every SharePoint admin needs to see this week is CVE-2026-65660, a high-severity code injection flaw in on-premises SharePoint Server that is now being actively exploited. The vulnerability lets an authenticated attacker with only low-level server access execute arbitrary code without any user interaction; researchers have also demonstrated chaining it with a separate authentication bypass to reach unauthenticated remote code execution. Microsoft shipped a fix in the August 2026 Patch Tuesday cycle, but once Viettel Security researchers disclosed technical details, threat intelligence firm Previdian observed exploitation attempts beginning September 24, including attackers dropping webshell backdoors within a day. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 25 and set a federal patch deadline of September 28, 2026 — today.

It bears repeating that this vulnerability targets on-premises SharePoint Server, not SharePoint Online tenants directly. If your organization runs SharePoint entirely in Microsoft 365, you are not exposed to CVE-2026-65660 itself. But few large organizations are that clean: hybrid search, hybrid taxonomy, and on-premises farms that federate into cloud identity are common enough that "we're a SharePoint Online shop" is often only half true. The attacks so far appear concentrated on sites that allow anonymous access, which is a configuration worth auditing regardless of patch status.

For any team that still operates a SharePoint Server farm — internal, hybrid, or a legacy instance nobody has gotten around to decommissioning — this is not a routine advisory to file away. Active exploitation plus a same-week federal deadline is the profile of a vulnerability that keeps getting used well after the news cycle fades, because patch cadence on on-prem farms tends to lag cloud services by months.

What to do: Confirm every SharePoint Server instance in your environment — including any farm you think of as "legacy" or "internal only" — is patched with the August 2026 security update (KB5002894) immediately, audit sites that allow anonymous access for signs of webshell activity, and if you believe you are a pure SharePoint Online tenant, verify that with an actual inventory rather than assumption.

SharePoint Framework 1.24: Copilot Components and React 18 Arrive

The SharePoint Framework (SPFx) team shipped SPFx 1.24 Beta 3 in August, and it is the most consequential developer-facing release of the year. The headline feature is Copilot Components — interactive UI elements, built with React and standard JavaScript, that render directly inside the Copilot canvas rather than on a SharePoint page. They can display inline or full-screen and deploy through the same SPFx tooling and tenant infrastructure developers already use, which means the skills your team has built for SharePoint web parts carry over almost directly to building for Copilot itself.

Alongside that, SPFx finally gets React 18 support, closing a long-standing gap between what the framework allowed and what the broader React ecosystem has been building against for years. The Copilot Component templates already run on React 18 in the beta, and Microsoft is explicitly asking the community to stress-test it for compatibility issues before general availability. This capability — previously previewed under the name "SharePoint Copilot Apps" — is now open to every tenant with no special licensing or consumption cost during preview, with sample solutions published at aka.ms/SPFx/Copilot/GitHub.

The timeline gives organizations a real planning window: SPFx 1.24 general availability lands in October 2026 with finalized Copilot Components and React 18 support, followed by SPFx 1.25 around December 2026/January 2027 with CLI general availability and navigation customizers. Microsoft also confirmed it has moved away from large quarterly SPFx drops toward smaller, more frequent preview releases — a cadence change worth noting for any team that plans SPFx upgrade cycles around a predictable schedule.

What to do: Pull SPFx 1.24 Beta 3 into a test environment now, run your existing component library against React 18 to surface breaking changes before GA, and have your development team review the Copilot Components sample solutions to scope what a first pilot component inside the Copilot canvas would look like for your organization.

SharePoint Advanced Management Matures Into a Full Governance Suite

SharePoint Advanced Management (SAM) has quietly evolved from a reporting add-on into what Microsoft is now positioning as a comprehensive content governance suite, organized around five pillars: sprawl control, oversharing control, lifecycle management, content relevance, and content resilience. The most notable new piece is the SharePoint Admin Agent, an AI assistant reachable from anywhere Copilot is available, launching with 15–20 supported actions on a path toward roughly 150. It analyzes governance data and can execute sequential administrative tasks on its own — but deliberately stops short of destructive actions, favoring archiving over deletion.

Two other additions matter for larger tenants specifically. Catalog Management lets admins structure sites into categories and groups that mirror how the business is actually organized, with automatic department and locale groupings plus custom categorization via CSV upload, property bag values, or Entra ID extension attributes — which makes it realistic to scope policies and insights to the parts of the tenant that actually need them. And a new file-level oversharing report, gated behind a distinct SharePoint Advanced Management Administrator role, finally delivers the long-requested "Everyone Except External Users" export that security teams have been asking for.

Most of these capabilities rolled out between June and August 2026, with Microsoft signaling more to come at Ignite. The strategic read for a consulting engagement is that SAM is no longer optional tooling for the largest enterprises — it is becoming the default lens through which Microsoft expects governance, oversharing, and lifecycle to be managed, and organizations that haven't licensed or configured it are increasingly the exception rather than the rule.

What to do: If you haven't enabled SharePoint Advanced Management, evaluate it against your current oversharing and lifecycle pain points; if you have, assign someone the new SharePoint Advanced Management Administrator role and pull the "Everyone Except External Users" report as a baseline before your next security review.

Copilot in SharePoint: AI Citations Analytics Rolls Out

Copilot in SharePoint picked up a capability this month that closes a real trust gap: AI citations analytics, now rolling out, tracks how SharePoint documents, news posts, and pages are actually being used by Copilot and other AI agents when they cite that content in an answer. Until now, content owners had little visibility into whether their documentation was being surfaced by AI at all, let alone how often — this gives them a usage signal that maps directly to which content is earning its keep as AI grounding material and which is being ignored.

This pairs with an already-launched improvement to Microsoft 365 Copilot's underlying retrieval: queries scoped to a specific SharePoint document library or folder now carry column metadata understanding, so a question aimed at a filtered subset of a library returns more precisely grounded answers instead of results that ignore the metadata a librarian carefully set up.

For any organization building an internal AI-skills program — which is squarely where Kiiro's own positioning sits — citations analytics is a genuinely useful measurement tool. It turns "we think our knowledge base is good AI grounding material" into something you can actually verify with data, and it gives content owners a concrete reason to keep high-value pages current rather than letting them go stale.

What to do: Once AI citations analytics is available in your tenant, pull a baseline report on which SharePoint content is being cited most and least by Copilot, and use that signal to prioritize which pages get refreshed first in any knowledge-hygiene effort tied to your AI rollout.

On the Roadmap: New Mobile Experience and a Reworked FAQ Web Part

Two items moving from "in development" to "coming soon" on the Microsoft 365 roadmap are worth flagging for planning purposes. First, a new SharePoint mobile experience for iOS and Android is set for October 2026, rebuilt around the personalized SharePoint Discover experience with improved browsing and a proper dark mode. For organizations that have leaned on the mobile app mainly as a lightweight document viewer, this redesign is a chance to revisit whether mobile SharePoint deserves a more active role in your intranet strategy.

Second, the FAQ web part is being split into two distinct authoring paths, also targeted for October 2026. Going forward it offers a standard, non-AI experience for manually creating and managing FAQs, while AI-assisted FAQ creation moves entirely into Copilot in SharePoint authoring — where authors write natural-language prompts against selected grounding sources to generate FAQ content compatible with the web part. Existing FAQs keep rendering as-is with no migration required, but the authoring workflow itself is changing meaningfully.

Neither change is disruptive on its own, but both are reminders that Microsoft continues to separate "the classic, predictable authoring tool" from "the AI-assisted version of the same tool" as a general pattern across SharePoint. Teams training end users on FAQ authoring or planning mobile-first intranet content should build the October timeline into their communication plans now.

What to do: Add the October 2026 mobile app redesign and FAQ web part changes to your end-user communication calendar, and if your organization authors FAQs regularly, pilot the new Copilot-assisted FAQ authoring flow as soon as it reaches your tenant.

Retirement Watch: The OTP Cutoff Lands This Week

The deadline flagged in last week's update is now essentially here. The SharePoint One-Time Passcode (OTP) external authentication method begins its production retirement on October 1, 2026 — just days away — with external sharing shifting to Microsoft Entra B2B guest accounts. Any external sharing links still depending on OTP are at risk of breaking the moment retirement completes in your environment, so this is the last practical window to confirm B2B guest provisioning for partners you collaborate with regularly.

Layer the new CVE-2026-65660 patch deadline on top of that OTP cutoff and this is a genuinely dense week for anything that touches authentication and external access in SharePoint. It's worth treating both as a single coordinated check rather than two unrelated line items, since teams that are already reviewing external sharing for the OTP transition are well positioned to also confirm anonymous-access exposure related to the SharePoint Server vulnerability at the same time.

Longer-horizon items remain unchanged from last week: classic publishing sites and classic user-created pages stop being creatable starting March 1, 2027, with existing pages going read-only by October 1, 2028; the four standalone SharePoint Online and OneDrive for Business plans stop new sales after May 2026 and renewals after January 2027; and the SharePoint Add-in, Azure ACS, and legacy IDCRL retirements are already behind us.

What to do: This week, verify external sharing links dependent on SPO OTP have a working Entra B2B guest fallback before October 1, and pair that review with a check for anonymous-access sites in light of the active SharePoint Server exploitation described above.


Sources