About the author
Chris Harrison
Chris owns Ness City Computer Service and has more than 30 years of IT experience helping Kansas homes and businesses keep their technology running and secure.
Running your own server gives you control. It also means you are responsible for patching it. In September 2026, CISA confirmed active attacks against three kinds of self-hosted software that small businesses, schools and towns commonly run.
A code-injection flaw in Microsoft SharePoint Server is being exploited, and Microsoft has confirmed attacks. This is about SharePoint you install and run yourself, often an older intranet or document system. If that server was reachable from the internet before it was updated, treat it as possibly compromised: look for unknown accounts, unfamiliar files and odd outbound connections, and change the service passwords.
A maximum-severity flaw lets an attacker read files from a self-managed GitLab server without logging in. Those files can include passwords, keys and source code. Fixed versions are 19.3.2, 19.2.6 and 19.1.8 (or newer). GitLab.com itself is not affected. If your server was exposed, update it and also change any passwords or keys stored in it, because a backup can restore a server but it can’t un-steal a secret.
CISA added three exploited Linux kernel flaws to its list on September 18. These affect web servers, hosting panels, firewalls and appliances built on Linux. The fix is ordinary: install your distribution’s current kernel security updates (Ubuntu, Debian, Red Hat and so on) and reboot so the new kernel actually runs. Don’t install a kernel straight from kernel.org on a production server just to match a version number.
Every self-hosted server needs four things: regular updates, monitoring, tested backups, and someone who notices when a warning like this comes out. If nobody in your business has that job, it may be time to have it managed, or to move that workload to a cloud service where the vendor patches it for you.
We set up, patch, monitor and back up business servers across central and western Kansas. Call us at 620-960-8711 and we will tell you whether your server is up to date.
Sources: Aviatrix: SharePoint CVE-2026-65660 · Rapid7: GitLab CVE-2026-85706 · Qualys: three Linux kernel CVEs
Want more free guides like this? Browse our Scam & Security Library — real examples of phishing emails, scam texts, fake pop-ups and more.
Chris owns Ness City Computer Service and has more than 30 years of IT experience helping Kansas homes and businesses keep their technology running and secure.
Call the local guys. We’re happy to help — no pressure.